Stránka 1 z 2

Pomoc se zavirovanem PC

Napsal: 22 črc 2014 03:31
od Lord-Diablo
Tak nez se mi povedlo napsat tento prispevek, musel jsem ho psat 5x, nyni ho radeji uz pisu v textaku.

Problem je v tom, ze se mi porad v rozsireni v chromu zobrazuje saave On. nekolikrat jsem ho uz odstranil, ale pak se tam vzdy vrati a dela mi porad nejake reklamy. Pak dalsi je, ze kdyz na neco kliknu, jako napriklad poprve na viry.cz tak se mi otevrela stranka vido.com nebo tak nejak kde jsou ty videe. Pri kliknuti mi se mi oteviraji dalsi stranky casto reklamni.

A posledni dobou se mi deje to, ze kdyz kliknu na video nebo fotku tak se mi rovnou otevre jako bych delal dvojlik. Nebo kliknu nekam na text nebo misto na webu a ozaci se mi cela stranka.

Uz nevim co mam delat. Posilam log z RSIT nastaveno na jeden mesic ale problemy trvaji myslim uz mnohem dele jo a porad se mi zahriva CPU. Jsem nekde na 96 stupnu, prepastovane a vyfoukane to uz vse mam.

Diky za pomoc.

Log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Denis at 2014-07-22 04:28:49
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 961 GB (67%) free of 1431 GB
Total RAM: 32744 MB (82% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:28:50, on 22.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Users\Denis\AppData\Roaming\ICQM\icq.exe
C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe
C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Denis\AppData\Local\Viber\Viber.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Users\Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
C:\Program Files (x86)\BlueStacks\HD-Agent.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Google\Drive\googledrivesync.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Denis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 88.86.121.137 www.ebay.com ebay.com
O1 - Hosts: 88.86.121.137 www.ebay.de ebay.de
O1 - Hosts: 88.86.121.137 www.fitness-extreme.cz fitness-extreme.cz
O1 - Hosts: 88.86.121.137 www.studio.cz studio.cz
O1 - Hosts: 88.86.121.137 www.fon-shop.eu fon-shop.eu
O1 - Hosts: 77.78.104.90 www.sexy-par.eu sexy-par.eu
O1 - Hosts: 88.86.121.137 www.import.cz import.cz
O1 - Hosts: 88.86.121.137 www.game-centrum.eu game-centrum.eu
O1 - Hosts: 88.86.121.137 www.wp.game-centrum.cz wp.game-centrum.cz
O1 - Hosts: 77.78.104.90 www.tabletlcd.cz tabletlcd.cz
O1 - Hosts: 88.86.121.137 www.faustuvdvur.cz faustuvdvur.cz
O1 - Hosts: 77.78.104.90 www.expres-eshop.cz expres-eshop.cz
O1 - Hosts: 77.78.104.90 www.expres-hosting.cz expres-hosting.cz
O1 - Hosts: 77.78.104.90 www.wpguru.eu wpguru.eu
O1 - Hosts: 77.78.104.90 www.hotelschwarz.cz hotelschwarz.cz
O1 - Hosts: 77.78.104.90 www.atv-brcars.cz atv-brcars.cz
O1 - Hosts: 77.78.104.90 www.chceme.to chceme.to
O1 - Hosts: 77.78.104.90 www.123auta.eu 123auta.eu
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: MySearch - {7243BBA5-2327-0FB9-E2D6-2666F2348E41} - C:\Program Files (x86)\MySearch\makUv.dll (file missing)
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: DigiCOuupOOn - {A98D882E-6A1C-1A4B-4067-77FB9DAFB43C} - C:\ProgramData\DigiCOuupOOn\7xj.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL
O2 - BHO: NNEwSaveR - {B615577B-A6A1-6893-B28E-716D03686BE6} - C:\ProgramData\NNEwSaveR\FtG85Y.dll
O2 - BHO: ssavoe on - {C98B7211-DBF9-F206-CFF0-4EA84DCD31C8} - C:\Program Files (x86)\ssavoe on\bCbpDX.dll (file missing)
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: GrabRez - {e1420d09-acc8-4efd-9965-e7ae3c5b977c} - C:\Program Files (x86)\GrabRez\GrabRezbho.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [HDDtoGOLaunch] C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
O4 - HKCU\..\Run: [SpeedUpMyComputer] C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss
O4 - HKCU\..\Run: [FixMyRegistry] C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss
O4 - HKCU\..\Run: [icq] C:\Users\Denis\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [SE] "C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Viber] "C:\Users\Denis\AppData\Local\Viber\Viber.exe" StartMinimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: MultiSkypeLauncher.lnk = C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Připojit cíl vazby k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Připojit k existujícímu PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Denis\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Denis\AppData\Roaming\ICQM\icq.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\hmipcore.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: c:\progra~2\sw-boo~1\assist~1.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service: HideMyIpSRV - Hide My IP - C:\Program Files (x86)\Hide My IP 6\HideMyIpSRV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MgAssist Service (MgAssistService) - Unknown owner - C:\Program Files (x86)\Mobogenie\MgAssist.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NitroPDFDriverCreatorReadSpool9 (NitroDriverReadSpool9) - Nitro PDF Software - C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
O23 - Service: Nalpeiron Licensing Service (nlsX86cc) - Nalpeiron Ltd. - C:\Windows\SysWOW64\NLSSRV32.EXE
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update GrabRez - Unknown owner - C:\Program Files (x86)\GrabRez\updateGrabRez.exe
O23 - Service: Util GrabRez - Unknown owner - C:\Program Files (x86)\GrabRez\bin\utilGrabRez.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 19650 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
taskeng.exe {04C52987-AB1E-4E3B-B526-B5B22893DFB9}
"C:\Program Files (x86)\Hide My IP 6\HideMyIpSRV.exe"
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files (x86)\Mobogenie\MgAssist.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
C:\Windows\SysWOW64\NLSSRV32.EXE
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\SmartTechnology\Software\ProfilerU.exe"
"C:\Program Files\SmartTechnology\Software\SaiMfd.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
"C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Users\Denis\AppData\Roaming\ICQM\icq.exe" -CU
"C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
"C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe" /c
"C:\Users\Denis\AppData\Local\Viber\Viber.exe" StartMinimized
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Users\Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe"
"C:\Program Files (x86)\BlueStacks\HD-Agent.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
"C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\GrabRez\updateGrabRez.exe"
"C:\Program Files (x86)\GrabRez\bin\utilGrabRez.exe"
"C:\Program Files (x86)\BlueStacks\HD-Service.exe" BstHdAndroidSvc Android
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe"
"C:\Program Files (x86)\BlueStacks\HD-Network.exe"
\??\C:\Windows\system32\conhost.exe "629870784-456822602-253480054-1567828056888891086-1169953762-505619237-1989504760
"C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe"
\??\C:\Windows\system32\conhost.exe "12608614811365600325-1389224845-2047319450-1827591098-16686509481126956050-2647714
"C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe"
\??\C:\Windows\system32\conhost.exe "-734224175-4755582811210114813-464180541-16222586721135549736-94394917585991544
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss cc5b775a-a941-4d68-9324-76d7a5e4f22a 1
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "1234948973-2064178693-1355599483-8625174047713090919993194021622270940859823043
\??\C:\Windows\system32\conhost.exe "1902030550-4363211358201711901068329829-1662775283-1483623346-2078754673-337227746
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosA2dp.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHid.exe"
"C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\\TosBtHsp.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="9156.0.1054370197\1799533718" --disable-image-transport-surface --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,1,14,27,33 --gpu-vendor-id=0x10de --gpu-device-id=0x1086 --gpu-driver-vendor=NVIDIA --gpu-driver-version=9.18.13.3788 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.2.1111296555\580714315" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.4.458226954\853585400" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.5.442477912\434581375" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.6.597060733\590472159" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.7.168896167\1181188738" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.8.1586793299\1524184735" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.10.392253645\568414493" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.11.222714111\744661182" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="9156.15.1205181798\492017042" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Windows\system32\notepad.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/FlashHardwareVideoDecode/HwVideo/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --enable-software-compositing --channel="9156.16.1118863593\1456175110" /prefetch:673131151
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/FlashHardwareVideoDecode/HwVideo/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --enable-software-compositing --channel="9156.594.294718889\682131510" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/FlashHardwareVideoDecode/HwVideo/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --renderer-print-preview --enable-software-compositing --channel="9156.603.1852989773\1535425819" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials="BrowserPreReadExperiment/100-pct-default/ChromeSuggestions/ML Kodachrome dev/EnhancedBookmarks/Default/ExtensionInstallVerification/None/FlashHardwareVideoDecode/HwVideo/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-1-Percent/group_36/UMA-Uniformity-Trial-10-Percent/group_01/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_13/UMA-Uniformity-Trial-50-Percent/group_01/WindowsLogoffRace/WindowsLogoffRace/" --enable-threaded-compositing --enable-delegated-renderer --enable-deadline-scheduling --extension-process --renderer-print-preview --enable-software-compositing --channel="9156.604.625111906\1161980216" /prefetch:673131151
"F:\RSITx64.exe"
"F:\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000Core.job - C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000UA.job - C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default

prefs.js - "browser.startup.homepage" - "http://search.gboxapp.com/"
prefs.js - "keyword.URL" - "http://websearch.fastosearch.info/?pid= ... =55&l=1&q="

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.2]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nitropdf.com/NitroPDF]
"Description"=NitroPDF Web Browser Plugin
"Path"=C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 14.0.0.145 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.60.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.60.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL


C:\Program Files (x86)\Mozilla Firefox\plugins\
npMeetingJoinPluginOC.dll
nppdf32.CZE
nppdf32.dll
nppdf32.HRV
nppdf32.HUN
nppdf32.POL
nppdf32.SKY
nppdf32.SLV

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02D891E4-51BF-E13A-3505-AD0580AD256C}]
Funn2SavE - C:\ProgramData\Funn2SavE\M.x64.dll [2014-06-24 402944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01 205416]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7243BBA5-2327-0FB9-E2D6-2666F2348E41}]
MySearch - C:\Program Files (x86)\MySearch\makUv.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-07-10 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-06-03 581824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8F7F047B-452E-E38B-D094-169EC7E5E67B}]
JOuniCooupuonn - C:\ProgramData\JOuniCooupuonn\TLSdQ_t.x64.dll [2014-06-17 402944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 877720]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B615577B-A6A1-6893-B28E-716D03686BE6}]
NNEwSaveR - C:\ProgramData\NNEwSaveR\FtG85Y.x64.dll [2014-04-05 474112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}]
ssavoe on - C:\Program Files (x86)\ssavoe on\bCbpDX.x64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2012-10-01 2322576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-07-10 211880]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-10-22 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01 139368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7243BBA5-2327-0FB9-E2D6-2666F2348E41}]
MySearch - C:\Program Files (x86)\MySearch\makUv.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-06-03 436600]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}]
DigiCOuupOOn - C:\ProgramData\DigiCOuupOOn\7xj.dll [2014-05-24 425472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL [2012-10-01 704664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B615577B-A6A1-6893-B28E-716D03686BE6}]
NNEwSaveR - C:\ProgramData\NNEwSaveR\FtG85Y.dll [2014-04-05 425472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}]
ssavoe on - C:\Program Files (x86)\ssavoe on\bCbpDX.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL [2012-10-01 1720976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e1420d09-acc8-4efd-9965-e7ae3c5b977c}]
GrabRez - C:\Program Files (x86)\GrabRez\GrabRezbho.dll [2014-02-19 249624]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-10-22 517688]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2014-05-08 343424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-11-30 11660904]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"ProfilerU"=C:\Program Files\SmartTechnology\Software\ProfilerU.exe [2013-04-16 454144]
"SaiMfd"=C:\Program Files\SmartTechnology\Software\SaiMfd.exe [2013-04-16 158208]
"Nvtmru"=C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe []
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-05-30 1279480]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-05-30 2352072]
"Cm108Sound"=C:\Windows\syswow64\RunDll32.exe [2009-07-14 44544]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AdobeBridge"= []
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2014-01-30 21822128]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"HDDtoGOLaunch"=C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe [2013-09-16 172032]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2014-06-29 3595608]
"KiesAirMessage"=C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup []
"SpeedUpMyComputer"=C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as /ss []
"FixMyRegistry"=C:\Program Files (x86)\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as /ss []
"icq"=C:\Users\Denis\AppData\Roaming\ICQM\icq.exe [2014-05-12 33664344]
"SE"=C:\Users\Denis\AppData\Roaming\SkypEmoticons\SE.exe [2014-06-10 5679008]
"Google Update"=C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe [2014-07-07 116648]
"Viber"=C:\Users\Denis\AppData\Local\Viber\Viber.exe [2014-06-19 930816]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"NUSB3MON"=C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [2010-11-17 113288]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START []
"JMB36X IDE Setup"=C:\Windows\RaidTool\xInsIDE.exe [2010-01-19 43632]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-07-04 3890208]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]
""= []
"Adobe Acrobat Speed Launcher"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [2014-05-08 41336]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2014-05-08 840568]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-01-20 811792]
"HP Software Update"=C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [2009-11-18 54576]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"SDTray"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [2014-04-25 4101584]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2008-05-27 413696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe
MultiSkypeLauncher.lnk - C:\Program Files (x86)\MultiSkypeLauncher\MultiSkypeLauncher.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HideMyIpSRV]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.tscc"=C:\Windows\SysWOW64\tsccvid64.dll
"MSVideo8"=VfWWDM32.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux1"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux2"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - "C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\dreamweaver.exe","%1"

======List of files/folders created in the last 1 month======

2014-07-21 23:32:27 ----D---- C:\rsit
2014-07-21 23:32:27 ----D---- C:\Program Files\trend micro
2014-07-20 23:39:56 ----D---- C:\Users\Denis\AppData\Roaming\Wirecast for YouTube
2014-07-20 23:39:53 ----D---- C:\Users\Denis\AppData\Roaming\Vara Software
2014-07-20 23:39:53 ----D---- C:\ProgramData\Telestream
2014-07-20 23:37:03 ----D---- C:\Program Files (x86)\Telestream
2014-07-20 23:32:37 ----D---- C:\ProgramData\Apple Computer
2014-07-20 23:31:42 ----D---- C:\ProgramData\Apple
2014-07-20 23:31:42 ----D---- C:\Program Files (x86)\Apple Software Update
2014-07-19 13:23:10 ----A---- C:\Windows\SYSWOW64\HideMyIpSRVOff.ini
2014-07-19 13:23:10 ----A---- C:\Windows\SYSWOW64\HideMyIpSRV.ini
2014-07-19 13:23:10 ----A---- C:\Windows\system32\HideMyIpSRVOff.ini
2014-07-19 13:16:20 ----A---- C:\Windows\system32\HMIPCore64.dll
2014-07-19 13:16:19 ----A---- C:\Windows\SYSWOW64\HMIPCore.dll
2014-07-19 13:16:10 ----D---- C:\Program Files (x86)\Hide My IP 6
2014-07-19 01:37:53 ----D---- C:\Program Files (x86)\Mozilla Firefox
2014-07-12 14:31:37 ----D---- C:\Users\Denis\AppData\Roaming\ViberPC
2014-07-11 16:33:27 ----D---- C:\Users\Denis\AppData\Roaming\HellShare Upload Manager
2014-07-11 16:33:05 ----D---- C:\Program Files (x86)\HellShare Upload Manager
2014-07-10 06:56:00 ----A---- C:\Windows\system32\javaws.exe
2014-07-10 06:55:50 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-10 06:55:50 ----A---- C:\Windows\system32\javaw.exe
2014-07-10 06:55:50 ----A---- C:\Windows\system32\java.exe
2014-07-10 06:55:38 ----D---- C:\Program Files\Java
2014-07-08 19:59:40 ----A---- C:\Windows\system32\aepdu.dll
2014-07-08 19:59:40 ----A---- C:\Windows\system32\aeinv.dll
2014-07-08 19:59:34 ----A---- C:\Windows\system32\win32k.sys
2014-07-08 19:59:31 ----A---- C:\Windows\SYSWOW64\osk.exe
2014-07-08 19:59:30 ----A---- C:\Windows\system32\osk.exe
2014-07-08 19:59:29 ----A---- C:\Windows\SYSWOW64\qedit.dll
2014-07-08 19:59:29 ----A---- C:\Windows\system32\qedit.dll
2014-07-08 19:59:28 ----A---- C:\Windows\system32\drivers\afd.sys
2014-07-08 19:59:24 ----A---- C:\Windows\system32\schannel.dll
2014-07-08 19:59:23 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-07-08 19:59:23 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-07-08 19:59:23 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-07-08 19:59:23 ----A---- C:\Windows\system32\kerberos.dll
2014-07-08 19:59:22 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-07-08 19:59:22 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-07-08 19:59:22 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-07-08 19:59:22 ----A---- C:\Windows\system32\wdigest.dll
2014-07-08 19:59:22 ----A---- C:\Windows\system32\TSpkg.dll
2014-07-08 19:59:22 ----A---- C:\Windows\system32\ncrypt.dll
2014-07-08 19:59:22 ----A---- C:\Windows\system32\msv1_0.dll
2014-07-08 19:59:21 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-07-08 19:59:21 ----A---- C:\Windows\system32\credssp.dll
2014-07-08 19:59:13 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-07-08 19:59:13 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-07-08 19:59:13 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-07-08 19:59:13 ----A---- C:\Windows\system32\iernonce.dll
2014-07-08 19:59:12 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-07-08 19:59:11 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-07-08 19:59:11 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-07-08 19:59:11 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-07-08 19:59:11 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-08 19:59:11 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-07-08 19:59:11 ----A---- C:\Windows\system32\iedkcs32.dll
2014-07-08 19:59:10 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-07-08 19:59:10 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-07-08 19:59:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-07-08 19:59:06 ----A---- C:\Windows\system32\urlmon.dll
2014-07-08 19:59:05 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-07-08 19:59:04 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-07-08 19:59:04 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-07-08 19:59:03 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-07-08 19:59:03 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-07-08 19:59:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-07-08 19:59:03 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-07-08 19:59:03 ----A---- C:\Windows\system32\dxtmsft.dll
2014-07-08 19:59:02 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-07-08 19:59:02 ----A---- C:\Windows\system32\msfeeds.dll
2014-07-08 19:59:01 ----A---- C:\Windows\system32\ie4uinit.exe
2014-07-08 19:59:00 ----A---- C:\Windows\system32\iesetup.dll
2014-07-08 19:58:59 ----A---- C:\Windows\system32\iertutil.dll
2014-07-08 19:58:58 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-07-08 19:58:58 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-07-08 19:58:58 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-07-08 19:58:57 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-07-08 19:58:57 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-07-08 19:58:57 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-07-08 19:58:57 ----A---- C:\Windows\system32\jsproxy.dll
2014-07-08 19:58:56 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-07-08 19:58:56 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-07-08 19:58:50 ----A---- C:\Windows\system32\dxtrans.dll
2014-07-08 19:58:32 ----A---- C:\Windows\system32\ieui.dll
2014-07-08 19:58:13 ----A---- C:\Windows\system32\ieframe.dll
2014-07-08 19:58:12 ----A---- C:\Windows\system32\mshtmled.dll
2014-07-08 19:58:11 ----A---- C:\Windows\system32\vbscript.dll
2014-07-08 19:58:11 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-07-08 19:58:11 ----A---- C:\Windows\system32\jscript9diag.dll
2014-07-08 19:58:11 ----A---- C:\Windows\system32\jscript9.dll
2014-07-08 19:58:11 ----A---- C:\Windows\system32\ieUnatt.exe
2014-07-08 19:58:11 ----A---- C:\Windows\system32\ieapfltr.dll
2014-07-08 19:58:10 ----A---- C:\Windows\system32\wininet.dll
2014-07-08 19:58:10 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-07-08 19:58:09 ----A---- C:\Windows\system32\msrating.dll
2014-07-08 19:58:08 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-08 19:58:08 ----A---- C:\Windows\system32\mshtml.dll
2014-07-08 19:57:23 ----A---- C:\Windows\system32\lsasrv.dll
2014-07-08 19:57:22 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-07-08 19:57:22 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-07-05 22:51:20 ----D---- C:\Program Files (x86)\NetoCouponn
2014-07-04 07:44:52 ----D---- C:\Program Files (x86)\FileSeek
2014-07-01 18:45:13 ----D---- C:\ProgramData\Wideblue installer
2014-07-01 03:49:33 ----D---- C:\ProgramData\NetoCouponn
2014-06-28 03:28:38 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-06-28 03:28:38 ----A---- C:\Windows\system32\DWrite.dll
2014-06-27 19:23:33 ----D---- C:\Users\Denis\AppData\Roaming\Generator
2014-06-27 19:23:08 ----D---- C:\Program Files (x86)\Generator
2014-06-24 03:20:13 ----D---- C:\ProgramData\Funn2SavE
2014-06-23 11:34:54 ----D---- C:\Users\Denis\AppData\Roaming\mojosoft
2014-06-23 11:34:54 ----D---- C:\Program Files (x86)\mojosoft

======List of files/folders modified in the last 1 month======

2014-07-22 04:28:50 ----D---- C:\Windows\Temp
2014-07-22 04:28:50 ----D---- C:\Windows\Prefetch
2014-07-22 00:18:54 ----D---- C:\Windows\system32\config
2014-07-22 00:16:59 ----SHD---- C:\System Volume Information
2014-07-21 23:32:27 ----RD---- C:\Program Files
2014-07-21 22:43:37 ----D---- C:\Users\Denis\AppData\Roaming\Dropbox
2014-07-21 22:43:31 ----D---- C:\Users\Denis\AppData\Roaming\Nitro PDF
2014-07-21 22:43:31 ----D---- C:\Users\Denis\AppData\Roaming\DropboxMaster
2014-07-21 22:41:30 ----D---- C:\Program Files (x86)\Origin
2014-07-21 22:40:55 ----D---- C:\ProgramData\NVIDIA
2014-07-21 22:40:07 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2014-07-21 04:08:14 ----RD---- C:\Program Files (x86)
2014-07-21 00:25:56 ----D---- C:\Program Files\Adobe
2014-07-21 00:25:14 ----D---- C:\Users\Denis\AppData\Roaming\Skype
2014-07-21 00:23:45 ----SHD---- C:\Windows\Installer
2014-07-21 00:23:36 ----D---- C:\Windows\winsxs
2014-07-21 00:22:56 ----D---- C:\Users\Denis\AppData\Roaming\BitTorrent
2014-07-20 23:39:53 ----HD---- C:\ProgramData
2014-07-20 23:38:55 ----D---- C:\Windows\system32\drivers
2014-07-20 23:38:55 ----D---- C:\Windows\inf
2014-07-20 23:38:54 ----D---- C:\Windows\system32\DriverStore
2014-07-20 23:38:54 ----D---- C:\Windows\system32\catroot
2014-07-20 23:34:26 ----D---- C:\Program Files\Internet Explorer
2014-07-20 23:34:25 ----D---- C:\Program Files (x86)\QuickTime
2014-07-20 23:32:37 ----D---- C:\Windows\SysWOW64
2014-07-20 23:31:45 ----D---- C:\Windows\system32\Tasks
2014-07-19 13:23:10 ----D---- C:\Windows\System32
2014-07-18 19:52:16 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-07-13 12:04:18 ----RSD---- C:\Windows\Fonts
2014-07-13 11:30:36 ----D---- C:\Windows\twain_32
2014-07-11 09:34:05 ----D---- C:\Program Files (x86)\Common Files
2014-07-10 06:55:34 ----D---- C:\Program Files (x86)\Java
2014-07-10 01:15:23 ----D---- C:\ProgramData\Origin
2014-07-09 23:52:41 ----D---- C:\ProgramData\Divine Elemente
2014-07-09 23:52:31 ----D---- C:\ProgramData\boost_interprocess
2014-07-09 04:13:02 ----D---- C:\Windows\rescache
2014-07-09 03:21:27 ----D---- C:\Program Files\Windows Journal
2014-07-09 03:21:26 ----SD---- C:\Windows\system32\CompatTel
2014-07-09 03:21:26 ----D---- C:\Windows\SYSWOW64\Dism
2014-07-09 03:21:26 ----D---- C:\Windows\system32\Dism
2014-07-09 03:21:26 ----D---- C:\Windows\system32\cs-CZ
2014-07-09 03:21:26 ----D---- C:\Windows\ehome
2014-07-09 03:21:25 ----D---- C:\Windows\SYSWOW64\en-US
2014-07-09 03:21:25 ----D---- C:\Windows\system32\en-US
2014-07-09 03:21:25 ----D---- C:\Program Files (x86)\Internet Explorer
2014-07-09 03:05:10 ----D---- C:\Windows\system32\MRT
2014-07-09 03:02:51 ----A---- C:\Windows\system32\MRT.exe
2014-07-09 00:54:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-07-08 19:57:06 ----D---- C:\Windows\system32\catroot2
2014-07-07 11:02:57 ----D---- C:\Users\Denis\AppData\Roaming\Mozilla
2014-07-07 11:02:50 ----D---- C:\Windows\Tasks
2014-07-05 22:51:21 ----D---- C:\ProgramData\4e63b05e907bdc7d
2014-07-02 17:34:29 ----D---- C:\Program Files (x86)\SW-Booster
2014-07-01 18:45:12 ----D---- C:\ProgramData\InstallMate
2014-06-30 22:21:52 ----SD---- C:\Users\Denis\AppData\Roaming\Microsoft
2014-06-28 03:40:13 ----AD---- C:\Windows
2014-06-27 19:23:09 ----D---- C:\Users\Denis\AppData\Roaming\Adobe
2014-06-25 01:30:31 ----D---- C:\ProgramData\Spybot - Search & Destroy
2014-06-23 13:20:24 ----D---- C:\Program Files (x86)\PdaNet for Android

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-06-03 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-06-03 208416]
R0 JRAID;JRAID; C:\Windows\system32\DRIVERS\jraid.sys [2010-08-10 120920]
R0 mv91xx;mv91xx; C:\Windows\system32\DRIVERS\mv91xx.sys [2010-11-22 303408]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 PxHlpa64;PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [2011-11-03 56208]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-06-03 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-06-03 1039096]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-06-03 423240]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-02-07 283064]
R1 Tosrfcom;Bluetooth RFCOMM; C:\Windows\System32\Drivers\tosrfcom.sys [2009-07-28 81768]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-06-03 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-06-03 79184]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-06-03 85328]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-01-20 115472]
R3 e1cexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver C; C:\Windows\system32\DRIVERS\e1c62x64.sys [2011-07-20 342704]
R3 e1qexpress;Intel(R) PCI Express Network Connection Driver Q; C:\Windows\system32\DRIVERS\e1q62x64.sys [2011-06-21 336048]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-11-30 2647528]
R3 MEIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-12-10 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-12-10 181248]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2013-11-28 197408]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-05-30 20256]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-03-31 40392]
R3 SaiK1708;SaiK1708; C:\Windows\system32\DRIVERS\SaiK1708.sys [2012-09-20 180544]
R3 SaiMini;SaiMini; C:\Windows\system32\DRIVERS\SaiMini.sys [2013-04-30 25120]
R3 SaiNtBus;SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [2013-04-30 52640]
R3 SaiU1708;SaiU1708; C:\Windows\system32\DRIVERS\SaiU1708.sys [2012-09-20 47168]
R3 tosporte;Bluetooth COM Port; C:\Windows\system32\DRIVERS\tosporte.sys [2009-06-17 54664]
R3 TSVAD_PCM;Wirecast Virtual Microphone Driver; C:\Windows\system32\drivers\tsvadpcm.sys [2014-04-15 33552]
R3 USBPNPA;USB PnP Sound Device Interface; C:\Windows\system32\drivers\CM10864.sys [2009-11-18 1308160]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver; C:\Windows\System32\Drivers\ssadadb.sys [2010-12-21 36328]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-22 108800]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-21 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 pneteth;PdaNet Broadband; C:\Windows\system32\DRIVERS\pneteth.sys [2011-11-25 15360]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-06-02 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-06-02 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-06-02 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-06-02 146920]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2010-12-21 136264]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2010-12-21 19016]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2010-12-21 172104]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 206080]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 tosrfbd;Bluetooth RFBUS; C:\Windows\system32\DRIVERS\tosrfbd.sys [2009-09-24 212072]
S3 tosrfbnp;Bluetooth RFBNEP; C:\Windows\System32\Drivers\tosrfbnp.sys [2009-06-19 50664]
S3 Tosrfhid;Bluetooth RFHID; C:\Windows\system32\DRIVERS\Tosrfhid.sys [2009-06-19 94336]
S3 tosrfnds;Bluetooth Personal Area Network; C:\Windows\system32\DRIVERS\tosrfnds.sys [2009-07-24 26472]
S3 Tosrfusb;Bluetooth USB Controller; C:\Windows\system32\DRIVERS\tosrfusb.sys [2009-09-14 58744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-06-03 50344]
R2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-01-20 402192]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-01-20 385808]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 HideMyIpSRV;HideMyIpSRV; C:\Program Files (x86)\Hide My IP 6\HideMyIpSRV.exe [2014-05-07 3849216]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2011-06-29 171688]
R2 MgAssistService;MgAssist Service; C:\Program Files (x86)\Mobogenie\MgAssist.exe [2014-03-04 70848]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 NitroDriverReadSpool9;NitroPDFDriverCreatorReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [2013-10-07 230920]
R2 nlsX86cc;Nalpeiron Licensing Service; C:\Windows\SysWOW64\NLSSRV32.EXE [2013-10-07 69640]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-05-30 1631008]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-05-30 21055432]
R2 NVSvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-05-20 927520]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-02-11 76888]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-04-25 1738200]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-04-25 2081752]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2014-05-20 413128]
R2 Update GrabRez;Update GrabRez; C:\Program Files (x86)\GrabRez\updateGrabRez.exe [2014-02-21 111384]
R2 Util GrabRez;Util GrabRez; C:\Program Files (x86)\GrabRez\bin\utilGrabRez.exe [2014-02-21 111384]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service; C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe [2009-10-21 193904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 d0e87c27;SW-Sustainer; C:\Windows\syswow64\rundll32.exe [2009-07-14 44544]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09 262320]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc []
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-06-19 111616]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-07-19 119408]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2012-12-08 178760]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2012-10-01 5132888]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-01-27 571816]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-02-04 1255736]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Pomoc se zavirovanem PC

Napsal: 22 črc 2014 04:11
od vyosek
Zdravim :)

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Pomoc se zavirovanem PC

Napsal: 23 črc 2014 00:51
od Lord-Diablo
Dekuji, rychlost je rapidne vetsi, ale ten dubleclick, nebo tak se to jmenuje je stale. Kdyz na neco kliknu hned se mi to otevre, dalsi problemy jsem prozatim nezaznamenal. ale uvidime co to udela behem vecera co budu neco delat.

Zde jsou logy

JRT

Kód: Vybrat vše

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by Denis on Łt 22.07.2014 at 22:42:30,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-901014225-1187277305-3373686348-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\secman.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B615577B-A6A1-6893-B28E-716D03686BE6}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{B615577B-A6A1-6893-B28E-716D03686BE6}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B615577B-A6A1-6893-B28E-716D03686BE6}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\mysearch"
Successfully deleted: [Folder] "C:\ProgramData\youtubeadblocker"
Successfully deleted: [Folder] "C:\Users\Denis\AppData\Roaming\newnext.me"
Failed to delete: [Folder] "C:\Program Files (x86)\mobogenie"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\Program Files (x86)\torntv.com"
Successfully deleted: [Folder] "C:\Program Files (x86)\youtubeadblocker"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\torntv.com"
Successfully deleted: [Folder] "C:\Users\Denis\AppData\Roaming\microsoft\windows\start menu\programs\mobogenie"
Successfully deleted: [Folder] "C:\Users\Denis\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"



~~~ FireFox

Successfully deleted the following from C:\Users\Denis\AppData\Roaming\mozilla\firefox\profiles\yfzr60ig.default\prefs.js

user_pref("browser.search.defaultenginename", "WebSearch");
user_pref("browser.search.defaultenginename,S", "WebSearch");
user_pref("browser.search.defaulturl", "hxxp://websearch.fastosearch.info/?pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55&l=1&q=");
user_pref("browser.search.order.1", "WebSearch");
user_pref("browser.search.order.1,S", "WebSearch");
user_pref("browser.search.selectedEngine", "WebSearch");
user_pref("browser.search.selectedEngine,S", "WebSearch");
user_pref("browser.startup.homepage", "hxxp://search.gboxapp.com/");
user_pref("extensions.0UxsWzqLJG.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\"
user_pref("extensions.1msGyTj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-
user_pref("extensions.98tOXlj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-
user_pref("extensions.9nSO.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||
user_pref("extensions.Uan2kWZM.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>
user_pref("extensions.Ulnymra5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>
user_pref("extensions.XLQrS6Ukw.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")
user_pref("extensions.b86.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.lV5TU.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1|
user_pref("extensions.r3UbcRmW.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>
user_pref("extensions.rlp.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||u
user_pref("extensions.u5Oj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||
user_pref("extensions.wiY4.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||
user_pref("keyword.URL", "hxxp://websearch.fastosearch.info/?pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55&l=1&q=");



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 22.07.2014 at 22:52:50,52
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ADW

Kód: Vybrat vše

# AdwCleaner v3.216 - Report created 22/07/2014 at 23:10:40
# Updated 17/07/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Denis - DENIS-PC
# Running from : C:\Users\Denis\Desktop\adwcleaner_3.216.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : d0e87c27
Service Deleted : MgAssistService
[#] Service Deleted : Update GrabRez
[#] Service Deleted : Util GrabRez
Service Deleted : wStLibG64

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\DigiCOuupOOn
Folder Deleted : C:\ProgramData\Funn2SavE
Folder Deleted : C:\ProgramData\JOuniCooupuonn
Folder Deleted : C:\ProgramData\MinIMumPriCEE
Folder Deleted : C:\ProgramData\NetoCouponn
Folder Deleted : C:\ProgramData\NNEwSaveR
Folder Deleted : C:\ProgramData\saave on
Folder Deleted : C:\ProgramData\safeweBu
Folder Deleted : C:\ProgramData\save on
Folder Deleted : C:\ProgramData\ssavoe on
Folder Deleted : C:\Program Files (x86)\Flash Player Pro
Folder Deleted : C:\Program Files (x86)\GrabRez
Folder Deleted : C:\Program Files (x86)\Mobogenie
Folder Deleted : C:\Program Files (x86)\SW-Booster
Folder Deleted : C:\Program Files (x86)\MinIMumPriCEE
Folder Deleted : C:\Program Files (x86)\NetoCouponn
Folder Deleted : C:\Windows\SysWOW64\SearchProtect
Folder Deleted : C:\Users\Administrator\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Administrator\AppData\Local\torch
Folder Deleted : C:\Users\Denis\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Denis\AppData\Local\genienext
Folder Deleted : C:\Users\Denis\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Denis\AppData\Local\torch
Folder Deleted : C:\Users\Denis\AppData\Roaming\EZDownloader
Folder Deleted : C:\Users\Denis\AppData\Roaming\SkypEmoticons
Folder Deleted : C:\Users\Denis\Documents\Mobogenie
Folder Deleted : C:\Users\Guest\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\Guest\AppData\Local\torch
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\torch
Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
[!] Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
[!] Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
[!] Folder Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
[!] Folder Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
[!] Folder Deleted : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
[!] Folder Deleted : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
File Deleted : C:\Windows\System32\drivers\wStLibG64.sys
File Deleted : C:\Users\Denis\daemonprocess.txt
File Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_continuetosave.info_0.localstorage-journal
File Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [se]
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager
Key Deleted : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\Classes\MiNNimUmPrice.MiNNimUmPrice
Key Deleted : HKLM\SOFTWARE\Classes\MiNNimUmPrice.MiNNimUmPrice.6.3
Key Deleted : HKLM\SOFTWARE\Classes\NEtuoCuouupon.NEtuoCuouupon
Key Deleted : HKLM\SOFTWARE\Classes\NEtuoCuouupon.NEtuoCuouupon.6.1
Key Deleted : HKLM\SOFTWARE\Classes\DigiiCOupon.DigiiCOupon
Key Deleted : HKLM\SOFTWARE\Classes\DigiiCOupon.DigiiCOupon.5.3
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S-860614263
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5F189DF5-2D05-472B-9091-84D9848AE48B}{d0e87c27}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{09F7595C-FEF2-ECEF-6749-F8A9AF8C6AF1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2C9EEE53-C8C1-8BD4-9755-975FCF706135}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8DBEF47A-099E-0897-A7FF-D75939A6C4BB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E1420D09-ACC8-4EFD-9965-E7AE3C5B977C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{09F7595C-FEF2-ECEF-6749-F8A9AF8C6AF1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2C9EEE53-C8C1-8BD4-9755-975FCF706135}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8DBEF47A-099E-0897-A7FF-D75939A6C4BB}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{09F7595C-FEF2-ECEF-6749-F8A9AF8C6AF1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{2C9EEE53-C8C1-8BD4-9755-975FCF706135}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{8DBEF47A-099E-0897-A7FF-D75939A6C4BB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8}
Key Deleted : HKCU\Software\RegisteredApplicationsEx
Key Deleted : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\Software\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\Software\MediaWatchV1
Key Deleted : HKLM\Software\SW-Booster
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\sw-boo~1\assist~1.dll
Data Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\sw-boo~1\assist~1.dll

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17207

Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v30.0 (cs)

[ File : C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default\prefs.js ]

Line Deleted : user_pref("extensions.0UxsWzqLJG.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumor[...]
Line Deleted : user_pref("extensions.1msGyTj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo[...]
Line Deleted : user_pref("extensions.98tOXlj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo[...]
Line Deleted : user_pref("extensions.9nSO.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.ne[...]
Line Deleted : user_pref("extensions.Uan2kWZM.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorob[...]
Line Deleted : user_pref("extensions.Ulnymra5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorob[...]
Line Deleted : user_pref("extensions.XLQrS6Ukw.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumoro[...]
Line Deleted : user_pref("extensions.b86.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.lV5TU.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.n[...]
Line Deleted : user_pref("extensions.r3UbcRmW.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorob[...]
Line Deleted : user_pref("extensions.rlp.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net[...]
Line Deleted : user_pref("extensions.u5Oj.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.ne[...]
Line Deleted : user_pref("extensions.wiY4.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.ne[...]

-\\ Google Chrome v33.0.1750.154

[ File : C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3310393&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP47704C8B-1A50-4566-8CA4-A0E11E7CD42C&q={searchTerms}&SSPV=
Deleted [Search Provider] : hxxp://dts.search.ask.com/sr?src=crb&gct=ds&appid=102&systemid=473&v=n9602-145&apn_uid=1072298143434135&apn_dtid=BND473&o=APN10640&apn_ptnrs=AG1&q={searchTerms}
Deleted [Search Provider] : hxxp://search.delta-homes.com/web/?utm_source=b&utm_medium=newgdp&utm_campaign=eXQ&utm_content=ds&from=newgdp&uid=WDCXWD1502FAEX-007BA0_WD-WMAY0368951389513&ts=1380449201&type=default&q={searchTerms}
Deleted [Search Provider] : hxxp://websearch.fastosearch.info/?l=1&q={searchTerms}&pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55
Deleted [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Deleted [Search Provider] : hxxp://wordpress.org/search/do-search.php?search={searchTerms}
Deleted [Startup_urls] : hxxp://websearch.fastosearch.info/?pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55
Deleted [Startup_urls] : hxxp://search.gboxapp.com/
Deleted [Homepage] : hxxp://www.trovigo.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP47704C8B-1A50-4566-8CA4-A0E11E7CD42C&SSPV=
Deleted [Extension] : adpkifcfcacgmnggcbpbjbkdijciiigm
Deleted [Extension] : kfnjcffbfckkndjmhkaiimjdangemefh

*************************

AdwCleaner[R0].txt - [15147 octets] - [22/07/2014 23:06:37]
AdwCleaner[R1].txt - [18552 octets] - [22/07/2014 23:08:23]
AdwCleaner[S0].txt - [18193 octets] - [22/07/2014 23:10:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [18254 octets] ##########
zoek ( s tim jsem mel docela problemy. Kdyz jsem ho chtel stahnout, avast mi ho nedovolil. A pak se mi skoro 30 min spoustel :) )

Kód: Vybrat vše

Zoek.exe v5.0.0.0 Updated 19-07-2014
Tool run by Denis on Łt 22.07.2014 at 23:27:39,46.
Microsoft Windows 7 Professional  6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Denis\Desktop\zoek.exe [Scan all users] [Script inserted] 

==== System Restore Info ======================

22.7.2014 23:30:55 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp. 
# 
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows. 
# 
# This file contains the mappings of IP addresses to host names. Each 
# entry should be kept on an individual line. The IP address should 
# be placed in the first column followed by the corresponding host name. 
# The IP address and the host name should be separated by at least one 
# space. 
# 
# Additionally, comments (such as these) may be inserted on individual 
# lines or following the machine name denoted by a '#' symbol. 
# 
# For example: 
# 
#      102.54.94.97     rhino.acme.com          # source server 
#       38.25.63.10     x.acme.com              # x client host 
 
# localhost name resolution is handle within DNS itself. 
127.0.0.1       localhost 
::1             localhost 

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-901014225-1187277305-3373686348-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{cea72c71-03c2-4da2-96a6-3e2bdfd3d07f} deleted successfully
HKEY_USERS\S-1-5-21-901014225-1187277305-3373686348-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{cea72c71-03c2-4da2-96a6-3e2bdfd3d07f} deleted successfully
HKEY_USERS\S-1-5-21-901014225-1187277305-3373686348-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_USERS\S-1-5-21-901014225-1187277305-3373686348-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{cea72c71-03c2-4da2-96a6-3e2bdfd3d07f} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home163.net deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default\prefs.js:

Added to C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default

user.js not found
---- Lines extensions.0UxsWzqLJG removed from prefs.js ----
user_pref("extensions.0UxsWzqLJG.epoch", "1405809886");
user_pref("extensions.0UxsWzqLJG.url", "http://couponbluemy.us/sync2/?q=hfZ9ofDSBShEAen0rjUEpchTB6lKDzt4okqAtNtVh7n0rjnEqTwErdk9pjwEtMFHhd9Fqda6rjYGrT
---- Lines extensions.1msGyTj removed from prefs.js ----
user_pref("extensions.1msGyTj.epoch", "1405809885");
user_pref("extensions.1msGyTj.url", "http://jpisyncer.info/sync2/?q=hfZ9ofq7B75MCyVUojw4rdYMg708BNmGWj8deShGheDUojw9rdgFrda8qdn8pihIC7n0rjnEqHw5rTs9qd
---- Lines extensions.98tOXlj removed from prefs.js ----
user_pref("extensions.98tOXlj.epoch", "1405809889");
user_pref("extensions.98tOXlj.url", "http://safe-easy.com/sync2/?q=hfZ9ofDSBShEAen0rjUEpchTB6lKDzt4okqAtNtVh7n0rjnEqTwErdk9qHnFtMFHhd9Fqda6rjYGrTn9qdU
---- Lines extensions.9nSO removed from prefs.js ----
user_pref("extensions.9nSO.epoch", "1405809885");
user_pref("extensions.9nSO.url", "http://get-jpi.info/sync2/?q=hfZ9oeZNAdkMCyVUojaMg708BNmGWj8deShGheDUojw9rdgGqdaFrdk8qihIC7n0rjnEqHw5rTs9qdn5tNhVCT9
---- Lines extensions.Uan2kWZM removed from prefs.js ----
user_pref("extensions.Uan2kWZM.epoch", "1405809889");
user_pref("extensions.Uan2kWZM.url", "http://jpiserver.info/sync2/?q=hfZ9oehMhy8IrihEAen0rchTB6lKDzt4okqAtNtVh7n0rjnEqHaFrdwHrda7tMFHhd9Fqda6rjYGrTn9q
---- Lines extensions.Ulnymra5 removed from prefs.js ----
user_pref("extensions.Ulnymra5.epoch", "1405809885");
user_pref("extensions.Ulnymra5.url", "http://musicforallpro.info/sync2/?q=hfZ9ofx6pftQtNbPhd9EtMqLDe49CNU0n8OMCMlNhd9Fqda7rjCErjr5rHYMBzqUojw9rdCFpdsG
---- Lines extensions.XLQrS6Ukw removed from prefs.js ----
user_pref("extensions.XLQrS6Ukw.epoch", "1405809881");
user_pref("extensions.XLQrS6Ukw.url", "http://toolkitfun.info/sync2/?q=hfZ9ofDSBShEAen0rjUEpchTB6lKDzt4okqAtNtVh7n0rjnEqTwErdk9rTaEtMFHhd9Fqda6rjYGrTn
---- Lines extensions.b86 removed from prefs.js ----
user_pref("extensions.b86.epoch", "1405809885");
user_pref("extensions.b86.url", "http://foreveryshare.ru/sync2/?q=hfZ9oeJQAchEAen0rchTB6lKDzt4okqAtNtVh7n0rjnEqjsGrds9rds7tMFHhd9Fqda6rjYGrTn9qdYMDMlG
---- Lines extensions.lV5TU removed from prefs.js ----
user_pref("extensions.lV5TU.epoch", "1405809883");
user_pref("extensions.lV5TU.url", "http://getjpinet.info/sync2/?q=hfZ9ofq7B75MCyVUojwFqTaMg708BNmGWj8deShGheDUojw9rdgErHw6rjaEqchIC7n0rjnEqHw5rTs9qdnE
---- Lines extensions.r3UbcRmW removed from prefs.js ----
user_pref("extensions.r3UbcRmW.epoch", "1405809888");
user_pref("extensions.r3UbcRmW.url", "http://transferbookmy.info/sync2/?q=hfZ9ofq7B75MCyVUojw4rdYMg708BNmGWj8deShGheDUojw9rdgFrda8qdYFqShIC7n0rjnEqHw5
---- Lines extensions.rlp removed from prefs.js ----
user_pref("extensions.rlp.epoch", "1405809885");
user_pref("extensions.rlp.url", "http://discountgetdirect.ru/sync2/?q=hfZ9oehUhGhEAen0rchTB6lKDzt4okqAtNtVh7n0rjnEqdaGrjaHrdk6tMFHhd9Fqda6rjYGrTn9qdYM
---- Lines extensions.u5Oj removed from prefs.js ----
user_pref("extensions.u5Oj.epoch", "1405810000");
user_pref("extensions.u5Oj.url", "http://taxtaxuk.eu/sync2/?q=hfZ9ofhMWdsMCyVUojaMg708BNmGWj8deShGheDUojw9rdkGrTsGqja9qGhIC7n0rjnEqHw5rTs9qTn5tNhVCT94
---- Lines extensions.wiY4 removed from prefs.js ----
user_pref("extensions.wiY4.epoch", "1405809890");
user_pref("extensions.wiY4.url", "http://getsyncer5.info/sync2/?q=hfZ9ofq7B75MCyVUojw4rdYMg708BNmGWj8deShGheDUojw9rdgFrda8qdYGrShIC7n0rjnEqHw5rTs9qdn4
---- Lines ext@MediaWatchV1home163.net modified from prefs.js ----

user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"web2pdfextension@web2pdf.adobedotcom\":{\"descriptor\":\"C:\\\\Pr
---- FireFox user.js and prefs.js backups ---- 

prefs_22.07.2014_2341_.backup

==== Deleting Files \ Folders ======================

C:\Users\Denis\AppData\LocalLow\{09F7595C-FEF2-ECEF-6749-F8A9AF8C6AF1} deleted
C:\Users\Denis\AppData\LocalLow\{2C9EEE53-C8C1-8BD4-9755-975FCF706135} deleted
C:\Users\Denis\AppData\LocalLow\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted
C:\Users\Denis\AppData\LocalLow\{8DBEF47A-099E-0897-A7FF-D75939A6C4BB} deleted
C:\Users\Denis\AppData\LocalLow\{A98D882E-6A1C-1A4B-4067-77FB9DAFB43C} deleted
C:\Users\Denis\AppData\LocalLow\{B1D92AEF-D72B-435A-FA31-E037F7508DB3} deleted
C:\Users\Denis\AppData\LocalLow\{B615577B-A6A1-6893-B28E-716D03686BE6} deleted
C:\Users\Denis\AppData\LocalLow\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{02D891E4-51BF-E13A-3505-AD0580AD256C} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{09F7595C-FEF2-ECEF-6749-F8A9AF8C6AF1} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{7243BBA5-2327-0FB9-E2D6-2666F2348E41} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{8DBEF47A-099E-0897-A7FF-D75939A6C4BB} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{8F7F047B-452E-E38B-D094-169EC7E5E67B} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{B615577B-A6A1-6893-B28E-716D03686BE6} deleted
C:\Users\Denis\AppData\Local\Packages\windows_ie_ac_001\AC\{C98B7211-DBF9-F206-CFF0-4EA84DCD31C8} deleted
C:\PROGRA~3\4e63b05e907bdc7d deleted
C:\Users\Denis\.android deleted
C:\PROGRA~2\COMMON~1\Wondershare deleted
C:\extensions.ini deleted
C:\Users\Denis\AppData\Roaming\Common deleted
C:\PROGRA~3\Supersoftware App deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Denis\AppData\Local\Wondershare deleted
C:\Users\Denis\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\Users\Denis\Downloads\adt-bundle-windows-x86_64-20131030.zip deleted
C:\Users\Denis\Downloads\graphics-inkydeals-Icons-Ninja-Bundle-Over-1500-Vector-Icons-Bonus.zip deleted
C:\Users\Denis\Downloads\vc-extensions-bundle_v1.3.zip deleted
C:\Users\Denis\Searches deleted
C:\Users\Denis\Downloads\SoftonicDownloader_for_morpheus.exe deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
F:\weby\123auta\opendoor14.rar.exe deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [03.06.2014 19:13]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [16.02.2014 02:46]

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default
4390CCD3790F8D9C427C0C29590C62D7	- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll -	Shockwave Flash
FB5621842FDABF9F8359775573498FBC	- C:\Users\Denis\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll -	Google Update
5CB01CF141E021DAAE96991A5BA57944	- C:\Users\Denis\AppData\Roaming\Mozilla\plugins\npo1d.dll -	Google Talk Plugin Video Renderer
DD31F0C436E4F5E6FA9783FF8A80ADC1	- C:\Users\Denis\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll -	Google Talk Plugin


==== Chrome Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[03.06.2014 19:13]
ppekllhafhodajijbbpffgiholmlobjp - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home163\ch\MediaWatchV1home163.crx[]

YoutubeAdblocker - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
MySearch - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
MySearch - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
Image Properties Context Menu - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
save onn - Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lenajbjhiamfgldckknempoihkhlknoe
YoutubeAdblocker - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
YoutubeAdblocker - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
Bejeweled - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm
Lockify - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiigoloogeminempipceaikpnaimbekd
SelectionBar - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\akgpcdalpfphjmfifkmfbpdmgdmeeaeo
Chrome Currency Converter - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\anbfhidldjknonaihbalghlebaijealk
Mobile & Tablet Emulator - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoncepgjhkfeapbalkebdoiialgofpan
Sothink Flash Downloader for Chrome - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\biceobciobbhhkplgocbaigojbnepcoi
Jotform Notifier - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpdcoccpkmfifppefclifememfhakacb
123ContactForm - Online Form Builder - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgolehhldemhadjnflinkaoldejibajd
Pushbullet - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd
Facebook Group Invite All - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjdageknjfakkahellcjcmoaiehaadel
Facebook Select All - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\clbcjpjecmkjagmnhgfojblhjhnalbda
SEO Site Tools - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\diahigjngdnkdgajdbpjdeomopbpkjjc
Hidden FLV Links - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\efbgjfpadfohojcjfdejolfaeicmkmgf
Yepi Play - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\egapbidakgfmcghmijhheclngmanenif
500px - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\egpociadnldbkfkjpmjoaibnbcoeplja
Pixlr-o-matic - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj
User-Agent Switcher - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffhkkpnppgnfaobgihpdblnhmmbodake
JotForm - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\finjdnhagcdiikmofgpgkmebpmbjcdhf
avast Online Security - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Wappalyzer - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gppongmhjkpfnbhagpmjfkannfbllamg
MySearch - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
Android APP Expres-Web.cz - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjbnlflepkneebimjgjhjfjohfpdjkda
Auto Replay for YouTube™ - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb
save onn - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\lenajbjhiamfgldckknempoihkhlknoe
Downloader - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp
Smartly generate QrCode - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfnbjbobhhoaekejilcmdkfomkndikho
3Dnator - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgjpfdjhlimkkdgnecbgnefdafbcncc
ScriptSafe - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf
Pub Toolbar - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc
Send from Gmail (by Google) - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc
Domain Availability Checker and Whois Lookup - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pokekecininnhejfkgcbnekjddnepope
Canvas Rider - Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk
YoutubeAdblocker - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
YoutubeAdblocker - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
MySearch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
MySearch - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
Image Properties Context Menu - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
YoutubeAdblocker - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
Image Properties Context Menu - HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
YoutubeAdblocker - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd
saave on - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk
save on - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip
MySearch - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek
saave On - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh
Image Properties Context Menu - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon
ssavoe on - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb
saifewoEEb - HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah

==== Chrome Fix ======================

C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wilmotveterinaryclinic.conduitapps.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_wilmotveterinaryclinic.conduitapps.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.superfish.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.best-deals-products.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_www.best-deals-products.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.best-deals-products.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.best-deals-products.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_features.en.softonic.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_features.en.softonic.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_moonsearch.com_0.localstorage deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_moonsearch.com_0.localstorage-journal deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_continuetosave.info_0.localstorage deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\bikagkgjeodpdnpefbciaglfgepfmemd deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ccmhehhkanepkbpkpnjddjlpdpbddeec deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ecocagiolicmikhihhcnkpihkdblaigb deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hedlpecjndpijdehjjnacjcldfpjfkfk deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jfopmgihohpgcepmicealpkofjgaciip deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jgmbkabkooljinaednmjcekkbccgpnek deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\kfnjcffbfckkndjmhkaiimjdangemefh deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\khagclindddokccfbmfmckaflngbmpon deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\mhlgfioollpcogifpngoemggfpbnenjb deleted successfully
C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Denis\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\omnppcfkinmhakbfepmfhicagkdhjhah deleted successfully
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lenajbjhiamfgldckknempoihkhlknoe deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\lenajbjhiamfgldckknempoihkhlknoe deleted successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\egapbidakgfmcghmijhheclngmanenif deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
No DefaultScope Set For HKCU

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE11SR"
{E54E69F1-487B-49A6-962F-DECC3BCF1806} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_13415"

==== Reset Google Chrome ======================

C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\0debf3a6-27b2-44f7-9e30-b1e80859a4fc deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\0e473631-3621-46cf-b9f8-3ff4fc79b16d deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\28905b37-92b0-4550-880c-11987db69d73 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\a5bced49-ed8e-4080-b221-b415c9b995ca deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ba378d0c-96fd-4771-81bf-0f55de9465a4 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\c2290d5f-da7e-458f-bd29-4dad37539460 deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\ppekllhafhodajijbbpffgiholmlobjp deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Denis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Denis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WX07SBVK will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Denis\AppData\Local\Mozilla\Firefox\Profiles\yfzr60ig.default\Cache will be emptied at reboot

==== Empty Chrome Cache ======================

C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1819 folders=455 655695813 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Denis\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Denis\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Denis\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WX07SBVK" not found

==== EOF on st 23.07.2014 at  0:11:18,95 ======================

Re: Pomoc se zavirovanem PC

Napsal: 23 črc 2014 07:04
od vyosek
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Pomoc se zavirovanem PC

Napsal: 23 črc 2014 15:30
od Lord-Diablo
Uz se miho nedari spustit. :(

Kód: Vybrat vše

http://oi62.tinypic.com/dzguna.jpg

Re: Pomoc se zavirovanem PC

Napsal: 23 črc 2014 20:32
od vyosek

Re: Pomoc se zavirovanem PC

Napsal: 24 črc 2014 02:56
od Lord-Diablo
Kdyz stahuju Stažení Farbar Recovery Scan Tool tak mi to hase, ze je to vir. Co s tim?

Re: Pomoc se zavirovanem PC

Napsal: 24 črc 2014 05:45
od vyosek
Docasne vypnete antivirovou ochranu, soubor je v poradku...

Re: Pomoc se zavirovanem PC

Napsal: 06 srp 2014 02:44
od Lord-Diablo
Odkaz ke stažení: http://vyosek.tym.cz/pro_usery/FRSTLauncher.exe

ted mi to zase pise:

Jejda! Prohlížeči Google Chrome se nepodařilo nalézt server vyosek.tym.cz

Re: Pomoc se zavirovanem PC

Napsal: 06 srp 2014 05:25
od vyosek
Spustte tedy jen samotny FRST

Re: Pomoc se zavirovanem PC

Napsal: 31 srp 2014 13:42
od Lord-Diablo
Tak zacinaji se mi sekat vsechny hry :(

Re: Pomoc se zavirovanem PC

Napsal: 31 srp 2014 15:12
od vyosek
Zdravim :)

:arrow: Po 25 dnech necinnosti opravdu nevim cim by to mohlo byt

:arrow: Dejte mi log z FRST

Re: Pomoc se zavirovanem PC

Napsal: 02 zář 2014 07:56
od Lord-Diablo
Zde je log posutel jsem to pres ten tool. Jestli jsem to udelal dobre, to bohuzel nevim :) :

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-08-2014 02
Ran by Denis (administrator) on DENIS-PC on 02-09-2014 08:50:54
Running from C:\Users\Denis\Desktop
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\36.0.1985.102\remoting_host.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\36.0.1985.102\remoting_host.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
() C:\Windows\SysWOW64\srvany.exe
() C:\Windows\KMService.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\System32\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Service.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-Network.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-BlockDevice.exe
(BlueStack Systems) C:\Program Files (x86)\BlueStacks\HD-SharedFolder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe
(Google Inc.) C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Users\Denis\AppData\Local\Viber\Viber.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Users\Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(ClanServers Hosting LLC) C:\Program Files (x86)\GameTracker\GSInGameService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
() C:\Program Files (x86)\Opera\23.0.1522.77\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe
(Adobe Systems, Incorporated) C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\Photoshop.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems, Inc.) C:\Program Files (x86)\Adobe\Adobe Dreamweaver CS6\Dreamweaver.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Opera Software) C:\Program Files (x86)\Opera\23.0.1522.77\opera.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11660904 2010-11-30] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ProfilerU] => C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] => C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [Cm108Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [ITSecMng] => C:\Program Files (x86)\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-09] (AVAST Software)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2014-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [811792 2014-01-20] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [21822128 2014-01-30] (Google)
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [HDDtoGOLaunch] => C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe [172032 2013-09-16] ()
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [Google Update] => C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-07-07] (Google Inc.)
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [Viber] => C:\Users\Denis\AppData\Local\Viber\Viber.exe [930816 2014-06-19] ()
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [GameTracker] => C:\Program Files (x86)\GameTracker\GTLite.exe [4019992 2013-12-19] (ClanServers Hosting LLC)
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_14_0_0_145_Plugin.exe [851632 2014-07-09] (Adobe Systems Incorporated)
HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\MountPoints2: {fc804f7a-8fc4-11e3-a7dc-f46d0444b06f} - G:\setup.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth Manager.lnk
ShortcutTarget: Bluetooth Manager.lnk -> C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Denis\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (http://tortoisesvn.net)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {E54E69F1-487B-49A6-962F-DECC3BCF1806} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Funn2SavE -> {02D891E4-51BF-E13A-3505-AD0580AD256C} -> C:\ProgramData\Funn2SavE\M.x64.dll No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: JOuniCooupuonn -> {8F7F047B-452E-E38B-D094-169EC7E5E67B} -> C:\ProgramData\JOuniCooupuonn\TLSdQ_t.x64.dll No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: NNEwSaveR -> {B615577B-A6A1-6893-B28E-716D03686BE6} -> C:\ProgramData\NNEwSaveR\FtG85Y.x64.dll No File
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\yfzr60ig.default
FF NewTab: hxxp://www.google.com/
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin -> C:\Users\Denis\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin -> C:\Users\Denis\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Denis\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Denis\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Denis\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Denis\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2014-02-04]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-02-16]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-03]
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovigo.com/?gd=&ctid=CT3314958&oct ... D42C&SSPV=
CHR StartupUrls: Default -> "chrome://apps/", "hxxp://google.com/", "hxxp://websearch.fastosearch.info/?pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55", "hxxp://search.gboxapp.com/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Translate) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2014-08-01]
CHR Extension: (Bejeweled) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm [2014-07-23]
CHR Extension: (SelectionBar) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\akgpcdalpfphjmfifkmfbpdmgdmeeaeo [2014-07-23]
CHR Extension: (Mobile & Tablet Emulator) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\aoncepgjhkfeapbalkebdoiialgofpan [2014-07-23]
CHR Extension: (Disk Google) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-03]
CHR Extension: (Web Developer) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm [2014-07-23]
CHR Extension: (Snooker) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjohiacoelemalmancnccjggomjnkfod [2014-07-23]
CHR Extension: (YouTube) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-03]
CHR Extension: (123ContactForm - Online Form Builder) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgolehhldemhadjnflinkaoldejibajd [2014-07-23]
CHR Extension: (Pushbullet) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2014-07-23]
CHR Extension: (Rozšíření pro webové stránky - WP Screenshot) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki [2014-07-23]
CHR Extension: (Vyhledávání Google) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-03]
CHR Extension: (SEO Site Tools) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\diahigjngdnkdgajdbpjdeomopbpkjjc [2014-07-23]
CHR Extension: (Hidden FLV Links) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\efbgjfpadfohojcjfdejolfaeicmkmgf [2014-07-23]
CHR Extension: (Pixlr-o-matic) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2014-07-23]
CHR Extension: (User-Agent Switcher) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffhkkpnppgnfaobgihpdblnhmmbodake [2014-07-23]
CHR Extension: (JotForm) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\finjdnhagcdiikmofgpgkmebpmbjcdhf [2014-07-23]
CHR Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\fllaojicojecljbmefodhfapmkghcbnh [2014-07-23]
CHR Extension: (Vzdálená plocha Chrome) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2014-07-26]
CHR Extension: (QR Code Generator) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcmhlmapohffdglflokbgknlknnmogbb [2014-07-23]
CHR Extension: (Wappalyzer) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\gppongmhjkpfnbhagpmjfkannfbllamg [2014-07-23]
CHR Extension: (theHunter) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2014-07-23]
CHR Extension: (Android APP Expres-Web.cz) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjbnlflepkneebimjgjhjfjohfpdjkda [2014-07-23]
CHR Extension: (Auto Replay for YouTube™) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\kanbnempkjnhadplbfgdaagijdbdbjeb [2014-07-23]
CHR Extension: (Image Downloader Plus) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdehodanbfebhhmpjfnlajdldkffehg [2014-07-23]
CHR Extension: (Smart QrCode Generator) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfnbjbobhhoaekejilcmdkfomkndikho [2014-07-23]
CHR Extension: (Peněženka Google) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-03]
CHR Extension: (Google Chrome to Phone Extension) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadboiipflhobonjjffjbfekfjcgkhco [2014-07-23]
CHR Extension: (Select All) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofcnbnhefnmjancehemliplicihbcjjb [2014-08-13]
CHR Extension: (ScriptSafe) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiigbmnaadbkfbmpbfijlflahbdbdgdf [2014-07-23]
CHR Extension: (Google Publisher Toolbar) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc [2014-07-23]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2014-07-23]
CHR Extension: (Gmail) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-03]
CHR Extension: (Canvas Rider) - C:\Users\Denis\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk [2014-07-23]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-09]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-09] (AVAST Software)
R2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [402192 2014-01-20] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [385808 2014-01-20] (BlueStack Systems, Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\36.0.1985.102\remoting_host.exe [51016 2014-06-26] (Google Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2014-08-06] () [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-01-18] (Hewlett-Packard) [File not signed]
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-10-07] (Nitro PDF Software)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-01-18] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-08-23] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-02-11] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [974016 2014-03-02] () [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 KMSServerService; C:\Users\Denis\AppData\Local\Temp\BA7.tmp\KMSServerService.exe [X]
S2 TunMirror; "C:\Users\Denis\AppData\Local\Temp\BA7.tmp\TunMirror.exe" [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-09] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-09] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-09] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-09] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-09] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-09] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-09] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-09] ()
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [115472 2014-01-20] (BlueStack Systems)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-02-07] (Disc Soft Ltd)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 SaiK1708; C:\Windows\System32\DRIVERS\SaiK1708.sys [180544 2012-09-20] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
R3 SaiU1708; C:\Windows\System32\DRIVERS\SaiU1708.sys [47168 2012-09-20] (Saitek)
R3 TSVAD_PCM; C:\Windows\System32\drivers\tsvadpcm.sys [33552 2014-04-15] (Windows (R) Win 7 DDK provider)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-02 08:50 - 2014-09-02 08:51 - 00036750 _____ () C:\Users\Denis\Desktop\FRST.txt
2014-09-02 08:50 - 2014-09-02 08:50 - 00015327 _____ () C:\Users\Denis\Desktop\LM.bat
2014-09-02 08:49 - 2014-09-02 08:50 - 00029696 _____ () C:\Users\Denis\AppData\Local\MSGBOX.EXE
2014-09-02 08:47 - 2014-09-02 08:48 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Desktop\FRSTLauncher (1).exe
2014-09-02 08:47 - 2014-09-02 08:47 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Downloads\FRSTLauncher.exe
2014-09-02 08:46 - 2014-09-02 08:50 - 00000000 ____D () C:\FRST
2014-09-02 08:45 - 2014-09-02 08:45 - 02104832 _____ (Farbar) C:\Users\Denis\Desktop\FRST64.exe
2014-09-02 08:43 - 2014-09-02 08:43 - 01222144 _____ () C:\Users\Denis\Downloads\RSITx64.exe
2014-08-30 20:46 - 2014-08-30 20:46 - 00877459 _____ () C:\Users\Denis\Downloads\[ETS2Downloads.com]streamline_10x8_V1.1.rar
2014-08-30 20:26 - 2014-08-30 20:26 - 01679731 _____ () C:\Users\Denis\Downloads\ItalyMod-ets2downloads.com.zip
2014-08-30 17:53 - 2014-08-31 09:03 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\TS3Client
2014-08-30 17:53 - 2014-08-30 17:53 - 00000933 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-08-30 17:53 - 2014-08-30 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-08-30 17:52 - 2014-08-30 17:53 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-08-30 17:51 - 2014-08-30 17:51 - 32520760 _____ (TeamSpeak Systems GmbH) C:\Users\Denis\Downloads\TeamSpeak3-Client-win64-3.0.13.1_master.exe
2014-08-30 17:33 - 2014-08-30 17:42 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\GameTracker
2014-08-30 17:22 - 2014-08-30 17:22 - 05782856 _____ () C:\Users\Denis\Downloads\GTSetup.exe
2014-08-30 17:22 - 2014-08-30 17:22 - 00001022 _____ () C:\Users\Denis\Desktop\GameTracker Lite.lnk
2014-08-30 17:22 - 2014-08-30 17:22 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameTracker Lite
2014-08-30 17:22 - 2014-08-30 17:22 - 00000000 ____D () C:\Program Files (x86)\GameTracker
2014-08-30 17:02 - 2014-08-30 18:38 - 00000900 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk
2014-08-30 17:02 - 2014-08-30 18:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer
2014-08-30 17:02 - 2014-08-30 17:02 - 00000000 ____D () C:\Users\Denis\Documents\ETS2MP
2014-08-30 17:00 - 2014-09-01 02:50 - 00000000 ____D () C:\Users\Denis\Documents\Euro Truck Simulator 2
2014-08-30 16:53 - 2014-08-30 16:53 - 02982097 _____ () C:\Users\Denis\Downloads\ets2mp_alpha_5401e565a97c2.zip
2014-08-30 15:29 - 2014-08-30 15:38 - 1011165184 _____ () C:\Users\Denis\Downloads\Gamer (2009) CZdub.avi
2014-08-30 15:01 - 2014-08-30 15:01 - 00001489 _____ () C:\Users\Public\Desktop\The Sims 4 Vytvořit Simíka – demo.lnk
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\Denis\Documents\Electronic Arts
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4 Vytvořit Simíka – demo
2014-08-30 15:01 - 2014-03-03 17:19 - 00447752 _____ (On2.com) C:\Windows\SysWOW64\vp6vfw.dll
2014-08-30 15:00 - 2014-08-30 15:00 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-30 08:04 - 2014-08-30 08:14 - 943736832 _____ () C:\Users\Denis\Downloads\TITANIC 2-2010-NOVINKY CZ Dabing.avi
2014-08-30 08:01 - 2014-08-30 08:13 - 1217009604 _____ () C:\Users\Denis\Downloads\Titanik.avi
2014-08-30 07:05 - 2014-08-30 07:21 - 1900393023 _____ () C:\Users\Denis\Downloads\Transformers 4 Zánik CZ DABING cam 2014 - Transformers age of extinction český dabing 2014.wmv
2014-08-30 05:53 - 2014-08-30 05:53 - 00484750 _____ () C:\Users\Denis\Downloads\export_20140830_0553.xml
2014-08-30 05:02 - 2014-08-30 05:02 - 17250450 _____ () C:\Users\Denis\Downloads\maxshop18.zip
2014-08-30 03:40 - 2014-08-30 03:47 - 817951128 ____R (SCS Software ) C:\Users\Denis\Downloads\EuroTruckSimulator2_1_12_1_setup.exe
2014-08-30 03:40 - 2014-08-30 03:40 - 00062815 _____ () C:\Users\Denis\Downloads\EuroTruckSimulator2_1_12_1_setup.exe.torrent
2014-08-29 08:10 - 2014-08-30 03:53 - 00001043 _____ () C:\Users\Public\Desktop\Euro Truck Simulator 2.lnk
2014-08-29 07:48 - 2014-08-30 16:24 - 03244068 _____ () C:\Users\Denis\Documents\Euro Truck Simulator 2.rar
2014-08-29 07:33 - 2014-08-29 07:33 - 00017093 _____ () C:\Users\Denis\Downloads\[kickass.to]euro.truck.simulator.2.gold.bundle.v.1.9.24.1s.4.dlc.2013.pc.repack.by.brick.tlrg.torrent
2014-08-29 04:01 - 2014-08-29 04:01 - 00483559 _____ () C:\Users\Denis\Downloads\kontakt_supercart.psd
2014-08-28 10:28 - 2014-08-23 04:07 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 10:28 - 2014-08-23 03:45 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-28 10:28 - 2014-08-23 02:59 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-28 01:04 - 2014-08-28 01:04 - 00028073 _____ () C:\Users\Denis\Downloads\gravityforms-export-2014-08-27.xml
2014-08-28 00:23 - 2014-08-28 00:23 - 00602662 _____ () C:\Users\Denis\Downloads\supercart.wordpress.2014-08-27.xml
2014-08-28 00:19 - 2014-08-28 00:20 - 12974326 _____ () C:\Users\Denis\Downloads\pageflex-cms - kingtheme.net.zip
2014-08-28 00:11 - 2014-08-28 00:12 - 45278743 _____ () C:\Users\Denis\Downloads\edison - kingtheme.net.rar
2014-08-26 22:49 - 2014-08-26 22:49 - 00002550 _____ () C:\Users\Denis\Desktop\kridlo_text.txt
2014-08-26 07:45 - 2014-08-26 07:45 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\AVG
2014-08-26 07:45 - 2014-08-26 07:45 - 00000000 ____D () C:\Users\Denis\AppData\Local\AVG
2014-08-26 07:44 - 2014-08-26 07:45 - 00000000 ____D () C:\ProgramData\AVG
2014-08-26 07:44 - 2014-08-26 07:44 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-08-26 07:44 - 2014-08-26 07:44 - 00000000 ____D () C:\Users\Denis\Documents\My Cheat Tables
2014-08-26 07:43 - 2014-08-26 07:43 - 00001091 _____ () C:\Users\Denis\Desktop\Cheat Engine.lnk
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\OpenCandy
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.4
2014-08-26 07:39 - 2014-08-26 07:40 - 09052192 _____ (Cheat Engine ) C:\Users\Denis\Downloads\CheatEngine64.exe
2014-08-25 13:48 - 2014-08-30 16:24 - 00000000 ____D () C:\Users\Denis\AppData\Local\SKIDROW
2014-08-25 08:23 - 2014-08-25 08:23 - 00016741 _____ () C:\Users\Denis\Downloads\[kickass.to]euro.truck.simulator.2.gold.bundle.v.1.9.24.1s.2013.pc.multi35.repack.by.r.g.Меchanics.torrent
2014-08-25 06:29 - 2014-08-25 06:29 - 00053557 _____ () C:\Users\Denis\Downloads\export_horal1.ods
2014-08-25 06:28 - 2014-08-25 06:28 - 00043413 _____ () C:\Users\Denis\Downloads\export_horal.ods
2014-08-25 06:27 - 2014-08-25 06:27 - 00327640 _____ () C:\Users\Denis\Downloads\export_20140825_0627.xml
2014-08-24 08:34 - 2014-08-24 08:34 - 09887266 _____ () C:\Users\Denis\Downloads\Music_Player_Mix (1).apk
2014-08-24 08:30 - 2014-08-24 08:30 - 05674994 _____ () C:\Users\Denis\Downloads\Music_Player_Mix.apk
2014-08-24 08:20 - 2014-08-24 08:20 - 09887266 _____ () C:\Users\Denis\Downloads\music_mix.apk
2014-08-23 05:04 - 2014-08-23 05:14 - 1580173904 _____ () C:\Users\Denis\Downloads\Bathory 2008 CZ.avi
2014-08-23 02:36 - 2014-08-23 02:36 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2014-08-23 01:40 - 2014-08-23 01:40 - 03759630 _____ () C:\Users\Denis\Downloads\codecanyon-6892199-ultimate-addons-for-visual-composer.zip
2014-08-23 00:25 - 2014-08-23 00:25 - 02247976 _____ () C:\Users\Denis\Downloads\battlelog-web-plugins_2.4.0_145.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-21 02:32 - 2014-08-21 02:32 - 00918440 _____ (Oracle Corporation) C:\Users\Denis\Downloads\chromeinstall-7u67.exe
2014-08-19 05:07 - 2014-08-19 05:13 - 729028608 _____ () C:\Users\Denis\Downloads\Van-Helsing--2-cz-vk.avi
2014-08-19 05:04 - 2014-08-19 05:12 - 786422952 _____ () C:\Users\Denis\Downloads\Van Helsing (2004) CZdub Akční,Dobrodružný,Horor,Fantasy.avi
2014-08-19 04:36 - 2014-08-19 05:02 - 1468557217 _____ () C:\Users\Denis\Downloads\Underworld.cz.5.1.avi
2014-08-19 04:35 - 2014-08-19 04:56 - 733898892 _____ () C:\Users\Denis\Downloads\Underworld 3 Vzpoura Lycanů (2009) CZ dabing HITOVKA.avi
2014-08-19 04:35 - 2014-08-19 04:56 - 733747200 _____ () C:\Users\Denis\Downloads\Underworld 2 Evolution (2005) CZ dabing HITOVKA.avi
2014-08-19 04:35 - 2014-08-19 04:56 - 730572800 _____ () C:\Users\Denis\Downloads\Underworld 4 cz dabing 2012.avi
2014-08-19 04:34 - 2014-08-19 04:59 - 976548864 _____ () C:\Users\Denis\Downloads\Underworld 1 (2003) CZ dabing HITOVKA.AVI
2014-08-18 15:08 - 2014-08-18 15:08 - 00000000 ____D () C:\Users\Denis\AppData\Local\Sniper3
2014-08-18 15:08 - 2014-08-18 15:08 - 00000000 ____D () C:\ProgramData\ALI213
2014-08-18 14:32 - 2014-08-18 14:32 - 00001734 _____ () C:\Users\Denis\Desktop\Play Sniper Elite 3.lnk
2014-08-17 23:12 - 2014-08-17 23:17 - 759062528 _____ () C:\Users\Denis\Downloads\Zrození ďábla-Devils Due (2014) CZdub.avi
2014-08-17 22:57 - 2014-05-05 09:43 - 01086885 _____ () C:\Users\Denis\Desktop\kosmetika Q10 rus.odp
2014-08-17 05:32 - 2014-08-17 05:32 - 00000699 _____ () C:\Users\Denis\Downloads\import_company.csv
2014-08-16 21:12 - 2014-08-16 21:18 - 725116928 _____ () C:\Users\Denis\Downloads\Sex nebo život! 2012 CZ Dabing.avi
2014-08-15 17:26 - 2014-08-15 17:28 - 30112022 _____ () C:\Users\Denis\Downloads\metrodir136.zip
2014-08-15 17:23 - 2014-08-15 17:24 - 47498534 _____ () C:\Users\Denis\Downloads\businessfinder-1.21.zip
2014-08-15 16:54 - 2014-08-15 16:54 - 00449608 _____ () C:\Users\Denis\Downloads\DownloadSetup__2299_i1175646558_il3.exe
2014-08-15 16:54 - 2014-08-15 16:54 - 00002103 _____ () C:\Users\Denis\Desktop\Continue installation - Download Manager Installation.lnk
2014-08-15 16:28 - 2014-08-15 16:28 - 00008952 _____ () C:\Users\Denis\Downloads\pmpro-network-master.zip
2014-08-15 16:17 - 2014-08-15 16:17 - 00118149 _____ () C:\Users\Denis\Downloads\wmpChrome (2).crx
2014-08-15 14:45 - 2014-08-15 18:08 - 00000000 ____D () C:\Users\Denis\Downloads\Sniper Elite 3 PC full game + DLC ^^nosTEAM^^
2014-08-15 14:43 - 2014-08-15 14:44 - 00371008 _____ () C:\Users\Denis\Downloads\Sniper_Elite_3_PC_full_game___DLC_^^nosTEAM^^.exe
2014-08-15 14:43 - 2014-08-15 14:43 - 00075329 _____ () C:\Users\Denis\Downloads\[kickass.to]sniper.elite.3.pc.full.game.dlc.nosteam.torrent
2014-08-15 03:03 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-15 03:03 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-15 03:03 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-15 03:03 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-15 03:03 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-15 03:03 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-15 03:02 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-15 03:02 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 14:50 - 2014-08-16 17:55 - 00000132 _____ () C:\Users\Denis\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-08-14 08:19 - 2014-08-01 01:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 08:19 - 2014-08-01 01:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 08:19 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 08:19 - 2014-07-25 16:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 08:19 - 2014-07-25 16:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 08:19 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 08:19 - 2014-07-25 15:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 08:19 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 08:19 - 2014-07-25 15:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 08:19 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 08:19 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 08:19 - 2014-07-25 15:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 08:19 - 2014-07-25 15:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 08:19 - 2014-07-25 15:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 08:19 - 2014-07-25 15:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-14 08:19 - 2014-07-25 15:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 08:19 - 2014-07-25 15:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 08:19 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 08:19 - 2014-07-25 14:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-14 08:19 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 08:19 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 08:19 - 2014-07-25 14:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 08:19 - 2014-07-25 14:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 08:19 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 08:19 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 08:19 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 08:19 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 08:19 - 2014-07-25 14:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 08:19 - 2014-07-25 14:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 08:19 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 08:19 - 2014-07-25 14:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 08:19 - 2014-07-25 14:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-14 08:19 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 08:19 - 2014-07-25 14:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 08:19 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 08:19 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 08:19 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 08:19 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 08:19 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 08:19 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 08:19 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 08:19 - 2014-07-25 13:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-14 08:19 - 2014-07-25 13:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 08:19 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 08:19 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 08:19 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 08:19 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 08:19 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 08:19 - 2014-07-25 13:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-14 08:19 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 08:19 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 08:19 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 08:19 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 08:19 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 08:19 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 08:19 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 07:42 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-08-14 07:42 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-08-14 07:42 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-08-14 07:42 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-08-14 07:42 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-08-14 07:42 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-14 07:42 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-14 07:42 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-14 07:42 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-14 07:42 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-14 07:42 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-08-14 07:42 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-14 07:37 - 2014-07-16 05:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-14 07:37 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-14 07:37 - 2014-06-16 04:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 07:37 - 2014-06-03 12:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 07:37 - 2014-06-03 12:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 07:37 - 2014-06-03 12:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 07:37 - 2014-06-03 12:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 07:37 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 07:37 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 07:37 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 07:36 - 2014-06-25 04:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-14 07:36 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-14 07:31 - 2014-07-14 04:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 07:31 - 2014-07-14 03:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 07:21 - 2014-08-07 04:06 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-14 07:21 - 2014-08-07 04:01 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-13 13:41 - 2014-08-13 13:41 - 174606558 _____ () C:\Users\Denis\AppData\Local\ACCCx2_7_1_418.zip.aamdownload
2014-08-13 13:41 - 2014-08-13 13:41 - 00002111 _____ () C:\Users\Denis\AppData\Local\ACCCx2_7_1_418.zip.aamdownload.aamd
2014-08-13 13:36 - 2014-08-13 13:36 - 00001034 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC (64 Bit).lnk
2014-08-13 13:36 - 2014-08-13 13:36 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-08-13 13:35 - 2014-08-13 13:35 - 00001206 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC.lnk
2014-08-13 13:31 - 2014-08-13 13:31 - 00001536 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
2014-08-13 13:31 - 2014-08-13 13:31 - 00001524 _____ () C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-08-13 07:20 - 2014-08-13 10:03 - 00000000 ____D () C:\Users\Denis\Downloads\FileSick.com-Heroes of Dragon Age for Android 2.0.0
2014-08-13 06:37 - 2014-08-13 06:37 - 00000000 ____D () C:\Users\Denis\Downloads\NeedForSpeedRivalsMulti11
2014-08-13 06:36 - 2014-08-13 06:36 - 00023849 _____ () C:\Users\Denis\Downloads\[kickass.to]need.for.speed.rivals.multi11.elamigos.torrent
2014-08-13 06:27 - 2014-08-13 06:27 - 00002289 _____ () C:\Users\Denis\Downloads\[kickass.to]heroes.of.dragon.age.for.android.2.0.0.filesick.torrent
2014-08-13 06:20 - 2014-08-13 06:25 - 00000000 ____D () C:\Users\Denis\Downloads\Adobe Photoshop CC 14.2 Final Multilanguage [ChingLiu]
2014-08-13 06:19 - 2014-08-13 06:19 - 00142154 _____ () C:\Users\Denis\Downloads\[kickass.to]adobe.photoshop.cc.14.2.final.multilanguage.chingliu.torrent
2014-08-13 05:59 - 2014-08-13 06:01 - 00000000 ____D () C:\Users\Denis\Downloads\WebSite X5 Template Pack 902 Multilingual + Keygen
2014-08-13 05:58 - 2014-08-13 05:58 - 00014235 _____ () C:\Users\Denis\Downloads\[kickass.to]website.x5.template.pack.902.multilingual.keygen.torrent
2014-08-13 03:08 - 2014-08-13 04:14 - 00000000 ____D () C:\Users\Denis\Desktop\test stranek
2014-08-13 02:37 - 2014-08-13 02:37 - 00000000 ____D () C:\Users\Denis\Documents\Incomedia
2014-08-13 02:35 - 2014-08-13 02:35 - 00000937 _____ () C:\Users\Denis\AppData\Local\recently-used.xbel
2014-08-13 02:31 - 2014-08-13 02:31 - 00001165 _____ () C:\Users\Public\Desktop\WebSite X5 Professional 10.lnk
2014-08-13 02:31 - 2014-08-13 02:31 - 00000000 ____D () C:\Users\Denis\AppData\Local\Incomedia
2014-08-13 02:31 - 2014-08-13 02:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebSite X5 v10 - Professional
2014-08-13 02:30 - 2014-08-13 02:31 - 00000000 ____D () C:\Program Files (x86)\WebSite X5 v10 - Professional
2014-08-13 02:20 - 2014-08-13 02:25 - 00000000 ____D () C:\Users\Denis\Downloads\Incomedia WebSite X5 Professional v10.1.6.48 Multilingual - [MUMBAI-TPB]
2014-08-13 02:19 - 2014-08-13 02:19 - 00110847 _____ () C:\Users\Denis\Downloads\[kickass.to]incomedia.website.x5.professional.v10.1.6.48.multilingual.mumbai.tpb.torrent
2014-08-13 02:08 - 2014-08-13 02:08 - 00000624 _____ () C:\Users\Denis\Downloads\Setup+Crack+Template.txt
2014-08-12 19:58 - 2014-08-12 19:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-08-12 19:58 - 2014-08-12 19:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-08-11 05:13 - 2014-08-11 05:19 - 961023674 _____ () C:\Users\Denis\Downloads\Pirati z Karibiku 4 Na vlnach podivna CZ.avi
2014-08-10 15:15 - 2014-08-10 15:19 - 735701026 _____ () C:\Users\Denis\Downloads\Piráti z Karibiku 3 Na konci světa (2007) CZ-dabing NOVINKA.avi
2014-08-09 21:12 - 2014-08-09 21:12 - 00001131 _____ () C:\Users\Denis\Desktop\Artisteer 4.lnk
2014-08-09 21:12 - 2014-08-09 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Artisteer 4
2014-08-09 21:12 - 2014-08-09 21:12 - 00000000 ____D () C:\Program Files (x86)\Artisteer 4
2014-08-09 21:04 - 2014-08-09 21:04 - 00000000 ____D () C:\Users\Denis\Desktop\test_sablony1
2014-08-09 21:00 - 2014-08-09 21:14 - 00000000 ____D () C:\Users\Denis\Downloads\Artisteer 4.1.0.59861 Final with Keygen-REPT by Senzati
2014-08-09 12:35 - 2014-08-09 12:35 - 00000000 ____D () C:\Users\Denis\Desktop\test_sablony
2014-08-09 12:23 - 2010-11-05 10:23 - 00144384 _____ () C:\Users\Denis\Desktop\keygen_Artisteer_3.0.exe
2014-08-09 12:09 - 2014-08-09 21:13 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Artisteer
2014-08-09 12:09 - 2014-08-09 12:09 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Apple Computer
2014-08-09 12:09 - 2014-08-09 12:09 - 00000000 ____D () C:\Users\Denis\AppData\Local\Apple Computer
2014-08-09 11:20 - 2014-08-09 11:20 - 00000000 ____D () C:\Windows\pss
2014-08-09 11:17 - 2014-08-09 11:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-08 22:26 - 2014-08-08 22:26 - 00000049 _____ () C:\Windows\SysWOW64\ScrRecX.log
2014-08-08 22:26 - 2008-08-18 19:18 - 00077824 _____ (Fox Magic Software) C:\Windows\SysWOW64\fmcodec.DLL
2014-08-06 16:47 - 2014-08-06 16:51 - 00000000 ____D () C:\Users\Denis\Downloads\NeoDownloader
2014-08-06 16:47 - 2014-08-06 16:47 - 00001108 _____ () C:\Users\Denis\Desktop\NeoDownloader Lite.lnk
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\NeoDownloader
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoDownloader Lite
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\Program Files (x86)\NeoDownloader Lite
2014-08-06 16:46 - 2014-08-06 16:47 - 04283816 _____ (Neowise Software ) C:\Users\Denis\Downloads\NeoDownloaderLiteSetup.exe
2014-08-06 11:25 - 2014-08-13 10:45 - 00000000 ____D () C:\Users\Denis\Downloads\Lynda WordPress (collection of 40 courses) (2010-2014)
2014-08-06 11:23 - 2014-08-06 11:23 - 00217954 _____ () C:\Users\Denis\Downloads\[kickass.to]lynda.wordpress.collection.of.40.courses.2010.2014.torrent
2014-08-06 10:59 - 2014-07-02 19:44 - 00609240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe
2014-08-06 10:55 - 2014-08-06 10:59 - 00003704 _____ () C:\Windows\System32\Tasks\AutoPico Daily Restart
2014-08-06 10:55 - 2014-08-06 10:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico
2014-08-06 10:55 - 2014-08-06 10:59 - 00000000 ____D () C:\Program Files\KMSpico
2014-08-06 10:51 - 2014-08-06 10:46 - 00151552 _____ () C:\Windows\KMService.exe
2014-08-06 10:51 - 2014-08-06 10:46 - 00008192 _____ () C:\Windows\SysWOW64\srvany.exe
2014-08-06 10:50 - 2014-08-06 10:50 - 00004424 _____ () C:\Users\Denis\Downloads\[kickass.to]kms.activator.office.2014.13.all.editions.windows.8.1.8.7.activator.kmspico.9.2.2.rc.simple.easy.torrent
2014-08-06 10:50 - 2014-08-06 10:50 - 00000000 ____D () C:\Users\Denis\Downloads\Microsoft Office Windows Activator(KMSpico 9.2.2 RC)
2014-08-06 10:50 - 2014-07-02 22:48 - 31512520 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 24196896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 22994208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 17555104 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 13922752 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 13835208 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 12866008 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-08-06 10:50 - 2014-07-02 22:48 - 11222048 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 04247000 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 03989960 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 01890080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434052.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 01539928 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434052.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00944928 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00907096 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00903624 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00869152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00846832 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00354016 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00166568 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-08-06 10:50 - 2014-07-02 22:48 - 00146480 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-08-06 10:40 - 2014-08-06 10:40 - 00000000 ____D () C:\Users\Denis\Documents\Vlastní šablony Office
2014-08-06 09:14 - 2014-08-06 09:17 - 346186209 _____ () C:\Users\Denis\Downloads\Mrtví a neklidní CZ - Warm Bodies (2013).mp4
2014-08-06 03:29 - 2014-08-06 03:31 - 00002565 _____ () C:\Windows\diagwrn.xml
2014-08-06 03:29 - 2014-08-06 03:31 - 00001908 _____ () C:\Windows\diagerr.xml
2014-08-06 03:16 - 2014-08-06 03:16 - 00000045 _____ () C:\Users\Denis\Downloads\microsoft-office-2013-plna-verze-cz-zdarma---odkaz-ke-stažení.txt
2014-08-06 03:15 - 2014-08-06 03:15 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-08-06 03:14 - 2014-08-06 03:14 - 00043256 _____ () C:\Windows\Logo.bmp
2014-08-06 03:13 - 2014-08-06 03:14 - 00000000 ____D () C:\Windows\Activator
2014-08-04 09:54 - 2014-08-04 10:00 - 934185872 _____ () C:\Users\Denis\Downloads\District 9(Sektor 9)_CZ dab.(akční,sci-fi,thriler,novinky).avi
2014-08-04 05:54 - 2014-08-04 06:07 - 2088705096 _____ () C:\Users\Denis\Downloads\Need for Speed (2014) HD 720p CZ dabing.avi
2014-08-04 05:47 - 2014-08-04 05:53 - 727287617 _____ () C:\Users\Denis\Downloads\Kronika Temna (Chronicles Of Riddick) 2004 (CZ DAB).avi
2014-08-04 05:43 - 2014-08-04 05:50 - 839389184 _____ () C:\Users\Denis\Downloads\Riddick 1 Černo černá tma - 2000 cz dab.n@y.avi
2014-08-03 23:51 - 2014-08-03 23:52 - 03006258 _____ () C:\Users\Denis\Downloads\freemorphing21.zip
2014-08-03 01:28 - 2014-08-03 01:39 - 1793675264 _____ () C:\Users\Denis\Downloads\Světová válka Z World War Z (2013) CZdub.avi
2014-08-03 01:19 - 2014-08-03 01:24 - 784441344 _____ () C:\Users\Denis\Downloads\Riddick (2013) CZ-Dabing NOVINKA.avi

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-09-02 08:51 - 2014-09-02 08:50 - 00036750 _____ () C:\Users\Denis\Desktop\FRST.txt
2014-09-02 08:50 - 2014-09-02 08:50 - 00015327 _____ () C:\Users\Denis\Desktop\LM.bat
2014-09-02 08:50 - 2014-09-02 08:49 - 00029696 _____ () C:\Users\Denis\AppData\Local\MSGBOX.EXE
2014-09-02 08:50 - 2014-09-02 08:46 - 00000000 ____D () C:\FRST
2014-09-02 08:48 - 2014-09-02 08:47 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Desktop\FRSTLauncher (1).exe
2014-09-02 08:47 - 2014-09-02 08:47 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Downloads\FRSTLauncher.exe
2014-09-02 08:45 - 2014-09-02 08:45 - 02104832 _____ (Farbar) C:\Users\Denis\Desktop\FRST64.exe
2014-09-02 08:44 - 2014-07-21 23:32 - 00000000 ____D () C:\Program Files\trend micro
2014-09-02 08:43 - 2014-09-02 08:43 - 01222144 _____ () C:\Users\Denis\Downloads\RSITx64.exe
2014-09-02 08:43 - 2014-02-03 20:24 - 01155395 _____ () C:\Windows\WindowsUpdate.log
2014-09-02 08:41 - 2014-02-05 07:48 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Skype
2014-09-02 08:36 - 2009-07-14 06:51 - 00013715 _____ () C:\Windows\setupact.log
2014-09-02 08:08 - 2014-02-03 20:51 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-02 08:07 - 2014-07-07 11:02 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000UA.job
2014-09-02 07:54 - 2014-02-09 19:54 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-02 06:28 - 2014-02-24 08:41 - 00000132 _____ () C:\Users\Denis\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-09-02 00:08 - 2014-02-03 20:51 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-01 23:04 - 2009-07-14 06:45 - 00035504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-01 23:04 - 2009-07-14 06:45 - 00035504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-01 11:07 - 2014-07-07 11:02 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000Core.job
2014-09-01 04:27 - 2014-07-12 14:30 - 00000000 ____D () C:\Users\Denis\AppData\Local\Viber
2014-09-01 02:50 - 2014-08-30 17:00 - 00000000 ____D () C:\Users\Denis\Documents\Euro Truck Simulator 2
2014-08-31 17:51 - 2014-02-03 20:55 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-31 09:04 - 2014-02-11 22:23 - 00000000 ____D () C:\ProgramData\Origin
2014-08-31 09:03 - 2014-08-30 17:53 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\TS3Client
2014-08-30 20:46 - 2014-08-30 20:46 - 00877459 _____ () C:\Users\Denis\Downloads\[ETS2Downloads.com]streamline_10x8_V1.1.rar
2014-08-30 20:26 - 2014-08-30 20:26 - 01679731 _____ () C:\Users\Denis\Downloads\ItalyMod-ets2downloads.com.zip
2014-08-30 18:38 - 2014-08-30 17:02 - 00000900 _____ () C:\Users\Public\Desktop\Play Euro Truck Simulator 2 Multiplayer.lnk
2014-08-30 18:38 - 2014-08-30 17:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Euro Truck Simulator 2 Multiplayer
2014-08-30 17:53 - 2014-08-30 17:53 - 00000933 _____ () C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2014-08-30 17:53 - 2014-08-30 17:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2014-08-30 17:53 - 2014-08-30 17:52 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-08-30 17:51 - 2014-08-30 17:51 - 32520760 _____ (TeamSpeak Systems GmbH) C:\Users\Denis\Downloads\TeamSpeak3-Client-win64-3.0.13.1_master.exe
2014-08-30 17:42 - 2014-08-30 17:33 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\GameTracker
2014-08-30 17:22 - 2014-08-30 17:22 - 05782856 _____ () C:\Users\Denis\Downloads\GTSetup.exe
2014-08-30 17:22 - 2014-08-30 17:22 - 00001022 _____ () C:\Users\Denis\Desktop\GameTracker Lite.lnk
2014-08-30 17:22 - 2014-08-30 17:22 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameTracker Lite
2014-08-30 17:22 - 2014-08-30 17:22 - 00000000 ____D () C:\Program Files (x86)\GameTracker
2014-08-30 17:02 - 2014-08-30 17:02 - 00000000 ____D () C:\Users\Denis\Documents\ETS2MP
2014-08-30 17:02 - 2014-04-21 07:20 - 00000000 ____D () C:\Games
2014-08-30 16:53 - 2014-08-30 16:53 - 02982097 _____ () C:\Users\Denis\Downloads\ets2mp_alpha_5401e565a97c2.zip
2014-08-30 16:28 - 2014-02-03 21:14 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-30 16:24 - 2014-08-29 07:48 - 03244068 _____ () C:\Users\Denis\Documents\Euro Truck Simulator 2.rar
2014-08-30 16:24 - 2014-08-25 13:48 - 00000000 ____D () C:\Users\Denis\AppData\Local\SKIDROW
2014-08-30 16:24 - 2014-06-05 05:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2014-08-30 15:38 - 2014-08-30 15:29 - 1011165184 _____ () C:\Users\Denis\Downloads\Gamer (2009) CZdub.avi
2014-08-30 15:01 - 2014-08-30 15:01 - 00001489 _____ () C:\Users\Public\Desktop\The Sims 4 Vytvořit Simíka – demo.lnk
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\Users\Denis\Documents\Electronic Arts
2014-08-30 15:01 - 2014-08-30 15:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4 Vytvořit Simíka – demo
2014-08-30 15:01 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-08-30 15:00 - 2014-08-30 15:00 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-30 14:51 - 2014-02-11 22:25 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2014-08-30 14:50 - 2014-02-11 22:23 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-08-30 08:14 - 2014-08-30 08:04 - 943736832 _____ () C:\Users\Denis\Downloads\TITANIC 2-2010-NOVINKY CZ Dabing.avi
2014-08-30 08:13 - 2014-08-30 08:01 - 1217009604 _____ () C:\Users\Denis\Downloads\Titanik.avi
2014-08-30 07:21 - 2014-08-30 07:05 - 1900393023 _____ () C:\Users\Denis\Downloads\Transformers 4 Zánik CZ DABING cam 2014 - Transformers age of extinction český dabing 2014.wmv
2014-08-30 05:53 - 2014-08-30 05:53 - 00484750 _____ () C:\Users\Denis\Downloads\export_20140830_0553.xml
2014-08-30 05:02 - 2014-08-30 05:02 - 17250450 _____ () C:\Users\Denis\Downloads\maxshop18.zip
2014-08-30 03:53 - 2014-08-29 08:10 - 00001043 _____ () C:\Users\Public\Desktop\Euro Truck Simulator 2.lnk
2014-08-30 03:49 - 2014-02-10 22:26 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\BitTorrent
2014-08-30 03:47 - 2014-08-30 03:40 - 817951128 ____R (SCS Software ) C:\Users\Denis\Downloads\EuroTruckSimulator2_1_12_1_setup.exe
2014-08-30 03:40 - 2014-08-30 03:40 - 00062815 _____ () C:\Users\Denis\Downloads\EuroTruckSimulator2_1_12_1_setup.exe.torrent
2014-08-29 08:26 - 2014-02-18 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-08-29 08:26 - 2014-02-18 18:51 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-29 08:26 - 2014-02-18 18:51 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-29 07:33 - 2014-08-29 07:33 - 00017093 _____ () C:\Users\Denis\Downloads\[kickass.to]euro.truck.simulator.2.gold.bundle.v.1.9.24.1s.4.dlc.2013.pc.repack.by.brick.tlrg.torrent
2014-08-29 07:21 - 2014-07-12 14:31 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\ViberPC
2014-08-29 07:20 - 2014-03-14 02:14 - 00000000 ___RD () C:\Users\Denis\Dropbox
2014-08-29 07:20 - 2014-03-14 02:12 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Dropbox
2014-08-29 07:20 - 2014-02-05 10:18 - 00000000 ___RD () C:\Users\Denis\Disk Google
2014-08-29 07:19 - 2009-07-14 06:45 - 05140368 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-29 07:18 - 2014-02-03 20:42 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-29 07:18 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-29 04:01 - 2014-08-29 04:01 - 00483559 _____ () C:\Users\Denis\Downloads\kontakt_supercart.psd
2014-08-28 09:19 - 2014-02-11 23:13 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-08-28 09:19 - 2010-11-21 05:47 - 00290610 _____ () C:\Windows\PFRO.log
2014-08-28 08:17 - 2014-02-13 17:31 - 00000000 ____D () C:\Users\Denis\Downloads\Pastelka2
2014-08-28 01:04 - 2014-08-28 01:04 - 00028073 _____ () C:\Users\Denis\Downloads\gravityforms-export-2014-08-27.xml
2014-08-28 00:23 - 2014-08-28 00:23 - 00602662 _____ () C:\Users\Denis\Downloads\supercart.wordpress.2014-08-27.xml
2014-08-28 00:20 - 2014-08-28 00:19 - 12974326 _____ () C:\Users\Denis\Downloads\pageflex-cms - kingtheme.net.zip
2014-08-28 00:12 - 2014-08-28 00:11 - 45278743 _____ () C:\Users\Denis\Downloads\edison - kingtheme.net.rar
2014-08-27 00:25 - 2014-02-11 23:13 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-08-27 00:25 - 2014-02-11 23:13 - 00214392 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-08-26 22:49 - 2014-08-26 22:49 - 00002550 _____ () C:\Users\Denis\Desktop\kridlo_text.txt
2014-08-26 07:45 - 2014-08-26 07:45 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\AVG
2014-08-26 07:45 - 2014-08-26 07:45 - 00000000 ____D () C:\Users\Denis\AppData\Local\AVG
2014-08-26 07:45 - 2014-08-26 07:44 - 00000000 ____D () C:\ProgramData\AVG
2014-08-26 07:44 - 2014-08-26 07:44 - 00000000 __SHD () C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
2014-08-26 07:44 - 2014-08-26 07:44 - 00000000 ____D () C:\Users\Denis\Documents\My Cheat Tables
2014-08-26 07:43 - 2014-08-26 07:43 - 00001091 _____ () C:\Users\Denis\Desktop\Cheat Engine.lnk
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\OpenCandy
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2014-08-26 07:43 - 2014-08-26 07:43 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.4
2014-08-26 07:40 - 2014-08-26 07:39 - 09052192 _____ (Cheat Engine ) C:\Users\Denis\Downloads\CheatEngine64.exe
2014-08-25 08:23 - 2014-08-25 08:23 - 00016741 _____ () C:\Users\Denis\Downloads\[kickass.to]euro.truck.simulator.2.gold.bundle.v.1.9.24.1s.2013.pc.multi35.repack.by.r.g.Меchanics.torrent
2014-08-25 06:29 - 2014-08-25 06:29 - 00053557 _____ () C:\Users\Denis\Downloads\export_horal1.ods
2014-08-25 06:28 - 2014-08-25 06:28 - 00043413 _____ () C:\Users\Denis\Downloads\export_horal.ods
2014-08-25 06:27 - 2014-08-25 06:27 - 00327640 _____ () C:\Users\Denis\Downloads\export_20140825_0627.xml
2014-08-24 08:34 - 2014-08-24 08:34 - 09887266 _____ () C:\Users\Denis\Downloads\Music_Player_Mix (1).apk
2014-08-24 08:30 - 2014-08-24 08:30 - 05674994 _____ () C:\Users\Denis\Downloads\Music_Player_Mix.apk
2014-08-24 08:20 - 2014-08-24 08:20 - 09887266 _____ () C:\Users\Denis\Downloads\music_mix.apk
2014-08-23 05:14 - 2014-08-23 05:04 - 1580173904 _____ () C:\Users\Denis\Downloads\Bathory 2008 CZ.avi
2014-08-23 04:07 - 2014-08-28 10:28 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 03:45 - 2014-08-28 10:28 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-23 02:59 - 2014-08-28 10:28 - 03163648 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-23 02:36 - 2014-08-23 02:36 - 00076152 _____ () C:\Windows\system32\PnkBstrA.exe
2014-08-23 02:08 - 2014-02-05 07:48 - 00000000 ____D () C:\ProgramData\Skype
2014-08-23 01:40 - 2014-08-23 01:40 - 03759630 _____ () C:\Users\Denis\Downloads\codecanyon-6892199-ultimate-addons-for-visual-composer.zip
2014-08-23 00:41 - 2014-02-11 23:14 - 00001200 _____ () C:\Users\Public\Desktop\Battlefield 4.lnk
2014-08-23 00:41 - 2014-02-11 23:14 - 00001176 _____ () C:\Users\Public\Desktop\Battlefield 4(64 bit).lnk
2014-08-23 00:25 - 2014-08-23 00:25 - 02247976 _____ () C:\Users\Denis\Downloads\battlelog-web-plugins_2.4.0_145.exe
2014-08-21 02:35 - 2014-02-07 19:07 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-21 02:34 - 2014-08-21 02:34 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-08-21 02:34 - 2014-08-21 02:34 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-08-21 02:34 - 2014-02-07 19:32 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-21 02:32 - 2014-08-21 02:32 - 00918440 _____ (Oracle Corporation) C:\Users\Denis\Downloads\chromeinstall-7u67.exe
2014-08-19 23:45 - 2014-07-09 00:59 - 00000000 ____D () C:\Users\Denis\Desktop\mira
2014-08-19 16:52 - 2014-06-03 22:01 - 00003828 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1391498859
2014-08-19 16:52 - 2014-02-04 09:27 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-08-19 05:13 - 2014-08-19 05:07 - 729028608 _____ () C:\Users\Denis\Downloads\Van-Helsing--2-cz-vk.avi
2014-08-19 05:12 - 2014-08-19 05:04 - 786422952 _____ () C:\Users\Denis\Downloads\Van Helsing (2004) CZdub Akční,Dobrodružný,Horor,Fantasy.avi
2014-08-19 05:02 - 2014-08-19 04:36 - 1468557217 _____ () C:\Users\Denis\Downloads\Underworld.cz.5.1.avi
2014-08-19 04:59 - 2014-08-19 04:34 - 976548864 _____ () C:\Users\Denis\Downloads\Underworld 1 (2003) CZ dabing HITOVKA.AVI
2014-08-19 04:56 - 2014-08-19 04:35 - 733898892 _____ () C:\Users\Denis\Downloads\Underworld 3 Vzpoura Lycanů (2009) CZ dabing HITOVKA.avi
2014-08-19 04:56 - 2014-08-19 04:35 - 733747200 _____ () C:\Users\Denis\Downloads\Underworld 2 Evolution (2005) CZ dabing HITOVKA.avi
2014-08-19 04:56 - 2014-08-19 04:35 - 730572800 _____ () C:\Users\Denis\Downloads\Underworld 4 cz dabing 2012.avi
2014-08-18 15:08 - 2014-08-18 15:08 - 00000000 ____D () C:\Users\Denis\AppData\Local\Sniper3
2014-08-18 15:08 - 2014-08-18 15:08 - 00000000 ____D () C:\ProgramData\ALI213
2014-08-18 14:32 - 2014-08-18 14:32 - 00001734 _____ () C:\Users\Denis\Desktop\Play Sniper Elite 3.lnk
2014-08-17 23:17 - 2014-08-17 23:12 - 759062528 _____ () C:\Users\Denis\Downloads\Zrození ďábla-Devils Due (2014) CZdub.avi
2014-08-17 23:00 - 2011-04-12 10:34 - 00672122 _____ () C:\Windows\system32\perfh005.dat
2014-08-17 23:00 - 2011-04-12 10:34 - 00142810 _____ () C:\Windows\system32\perfc005.dat
2014-08-17 23:00 - 2009-07-14 07:13 - 01593258 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-17 17:07 - 2014-02-03 20:57 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-08-17 05:32 - 2014-08-17 05:32 - 00000699 _____ () C:\Users\Denis\Downloads\import_company.csv
2014-08-16 21:18 - 2014-08-16 21:12 - 725116928 _____ () C:\Users\Denis\Downloads\Sex nebo život! 2012 CZ Dabing.avi
2014-08-16 17:55 - 2014-08-14 14:50 - 00000132 _____ () C:\Users\Denis\AppData\Roaming\Formát PNG Adobe CC – předvolby
2014-08-15 18:08 - 2014-08-15 14:45 - 00000000 ____D () C:\Users\Denis\Downloads\Sniper Elite 3 PC full game + DLC ^^nosTEAM^^
2014-08-15 17:28 - 2014-08-15 17:26 - 30112022 _____ () C:\Users\Denis\Downloads\metrodir136.zip
2014-08-15 17:24 - 2014-08-15 17:23 - 47498534 _____ () C:\Users\Denis\Downloads\businessfinder-1.21.zip
2014-08-15 16:54 - 2014-08-15 16:54 - 00449608 _____ () C:\Users\Denis\Downloads\DownloadSetup__2299_i1175646558_il3.exe
2014-08-15 16:54 - 2014-08-15 16:54 - 00002103 _____ () C:\Users\Denis\Desktop\Continue installation - Download Manager Installation.lnk
2014-08-15 16:28 - 2014-08-15 16:28 - 00008952 _____ () C:\Users\Denis\Downloads\pmpro-network-master.zip
2014-08-15 16:17 - 2014-08-15 16:17 - 00118149 _____ () C:\Users\Denis\Downloads\wmpChrome (2).crx
2014-08-15 14:44 - 2014-08-15 14:43 - 00371008 _____ () C:\Users\Denis\Downloads\Sniper_Elite_3_PC_full_game___DLC_^^nosTEAM^^.exe
2014-08-15 14:43 - 2014-08-15 14:43 - 00075329 _____ () C:\Users\Denis\Downloads\[kickass.to]sniper.elite.3.pc.full.game.dlc.nosteam.torrent
2014-08-15 13:50 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-08-15 12:28 - 2014-03-14 02:14 - 00001025 _____ () C:\Users\Denis\Desktop\Dropbox.lnk
2014-08-15 12:28 - 2014-03-14 02:13 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-15 07:54 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-15 03:19 - 2014-02-04 09:32 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-15 03:10 - 2014-02-04 09:32 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-15 03:00 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-08-13 17:10 - 2014-02-07 09:36 - 00007680 _____ () C:\Users\Denis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-13 14:03 - 2014-02-04 05:10 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Adobe
2014-08-13 13:41 - 2014-08-13 13:41 - 174606558 _____ () C:\Users\Denis\AppData\Local\ACCCx2_7_1_418.zip.aamdownload
2014-08-13 13:41 - 2014-08-13 13:41 - 00002111 _____ () C:\Users\Denis\AppData\Local\ACCCx2_7_1_418.zip.aamdownload.aamd
2014-08-13 13:41 - 2014-02-04 05:10 - 00000000 ____D () C:\Users\Denis\AppData\Local\Adobe
2014-08-13 13:36 - 2014-08-13 13:36 - 00001034 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC (64 Bit).lnk
2014-08-13 13:36 - 2014-08-13 13:36 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-08-13 13:36 - 2014-02-04 05:13 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-08-13 13:36 - 2014-02-04 05:13 - 00000000 ____D () C:\Program Files\Adobe
2014-08-13 13:35 - 2014-08-13 13:35 - 00001206 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC.lnk
2014-08-13 13:35 - 2014-02-04 05:14 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-08-13 13:35 - 2014-02-03 20:50 - 00115120 _____ () C:\Users\Denis\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-13 13:33 - 2014-02-04 05:10 - 00000000 ____D () C:\ProgramData\Adobe
2014-08-13 13:31 - 2014-08-13 13:31 - 00001536 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
2014-08-13 13:31 - 2014-08-13 13:31 - 00001524 _____ () C:\Users\Public\Desktop\Adobe Application Manager.lnk
2014-08-13 10:45 - 2014-08-06 11:25 - 00000000 ____D () C:\Users\Denis\Downloads\Lynda WordPress (collection of 40 courses) (2010-2014)
2014-08-13 10:03 - 2014-08-13 07:20 - 00000000 ____D () C:\Users\Denis\Downloads\FileSick.com-Heroes of Dragon Age for Android 2.0.0
2014-08-13 06:37 - 2014-08-13 06:37 - 00000000 ____D () C:\Users\Denis\Downloads\NeedForSpeedRivalsMulti11
2014-08-13 06:36 - 2014-08-13 06:36 - 00023849 _____ () C:\Users\Denis\Downloads\[kickass.to]need.for.speed.rivals.multi11.elamigos.torrent
2014-08-13 06:27 - 2014-08-13 06:27 - 00002289 _____ () C:\Users\Denis\Downloads\[kickass.to]heroes.of.dragon.age.for.android.2.0.0.filesick.torrent
2014-08-13 06:25 - 2014-08-13 06:20 - 00000000 ____D () C:\Users\Denis\Downloads\Adobe Photoshop CC 14.2 Final Multilanguage [ChingLiu]
2014-08-13 06:19 - 2014-08-13 06:19 - 00142154 _____ () C:\Users\Denis\Downloads\[kickass.to]adobe.photoshop.cc.14.2.final.multilanguage.chingliu.torrent
2014-08-13 06:01 - 2014-08-13 05:59 - 00000000 ____D () C:\Users\Denis\Downloads\WebSite X5 Template Pack 902 Multilingual + Keygen
2014-08-13 05:58 - 2014-08-13 05:58 - 00014235 _____ () C:\Users\Denis\Downloads\[kickass.to]website.x5.template.pack.902.multilingual.keygen.torrent
2014-08-13 04:14 - 2014-08-13 03:08 - 00000000 ____D () C:\Users\Denis\Desktop\test stranek
2014-08-13 02:37 - 2014-08-13 02:37 - 00000000 ____D () C:\Users\Denis\Documents\Incomedia
2014-08-13 02:35 - 2014-08-13 02:35 - 00000937 _____ () C:\Users\Denis\AppData\Local\recently-used.xbel
2014-08-13 02:35 - 2014-03-12 19:17 - 00000000 ____D () C:\Users\Denis\.gimp-2.8
2014-08-13 02:31 - 2014-08-13 02:31 - 00001165 _____ () C:\Users\Public\Desktop\WebSite X5 Professional 10.lnk
2014-08-13 02:31 - 2014-08-13 02:31 - 00000000 ____D () C:\Users\Denis\AppData\Local\Incomedia
2014-08-13 02:31 - 2014-08-13 02:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebSite X5 v10 - Professional
2014-08-13 02:31 - 2014-08-13 02:30 - 00000000 ____D () C:\Program Files (x86)\WebSite X5 v10 - Professional
2014-08-13 02:25 - 2014-08-13 02:20 - 00000000 ____D () C:\Users\Denis\Downloads\Incomedia WebSite X5 Professional v10.1.6.48 Multilingual - [MUMBAI-TPB]
2014-08-13 02:19 - 2014-08-13 02:19 - 00110847 _____ () C:\Users\Denis\Downloads\[kickass.to]incomedia.website.x5.professional.v10.1.6.48.multilingual.mumbai.tpb.torrent
2014-08-13 02:08 - 2014-08-13 02:08 - 00000624 _____ () C:\Users\Denis\Downloads\Setup+Crack+Template.txt
2014-08-12 19:58 - 2014-08-12 19:58 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-08-12 19:58 - 2014-08-12 19:58 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-08-12 19:58 - 2014-07-20 23:31 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-08-11 05:19 - 2014-08-11 05:13 - 961023674 _____ () C:\Users\Denis\Downloads\Pirati z Karibiku 4 Na vlnach podivna CZ.avi
2014-08-10 15:19 - 2014-08-10 15:15 - 735701026 _____ () C:\Users\Denis\Downloads\Piráti z Karibiku 3 Na konci světa (2007) CZ-dabing NOVINKA.avi
2014-08-09 21:14 - 2014-08-09 21:00 - 00000000 ____D () C:\Users\Denis\Downloads\Artisteer 4.1.0.59861 Final with Keygen-REPT by Senzati
2014-08-09 21:13 - 2014-08-09 12:09 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Artisteer
2014-08-09 21:12 - 2014-08-09 21:12 - 00001131 _____ () C:\Users\Denis\Desktop\Artisteer 4.lnk
2014-08-09 21:12 - 2014-08-09 21:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Artisteer 4
2014-08-09 21:12 - 2014-08-09 21:12 - 00000000 ____D () C:\Program Files (x86)\Artisteer 4
2014-08-09 21:04 - 2014-08-09 21:04 - 00000000 ____D () C:\Users\Denis\Desktop\test_sablony1
2014-08-09 12:35 - 2014-08-09 12:35 - 00000000 ____D () C:\Users\Denis\Desktop\test_sablony
2014-08-09 12:09 - 2014-08-09 12:09 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Apple Computer
2014-08-09 12:09 - 2014-08-09 12:09 - 00000000 ____D () C:\Users\Denis\AppData\Local\Apple Computer
2014-08-09 11:20 - 2014-08-09 11:20 - 00000000 ____D () C:\Windows\pss
2014-08-09 11:18 - 2014-02-03 20:58 - 00001972 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-08-09 11:18 - 2014-02-03 20:57 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-08-09 11:17 - 2014-08-09 11:17 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-08-09 11:17 - 2014-06-03 19:13 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-08-09 11:17 - 2014-02-03 20:57 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-08-09 11:17 - 2014-02-03 20:57 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-08-09 07:14 - 2014-05-12 10:19 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\Nitro PDF
2014-08-09 04:24 - 2014-06-19 14:03 - 01285876 _____ () C:\Users\Denis\Downloads\SpyHunter-4.1.11.0-+-Crack.rar
2014-08-09 04:16 - 2014-02-07 11:48 - 00000000 ____D () C:\Users\Denis\Desktop\HDD drive
2014-08-09 02:32 - 2014-07-22 23:20 - 00000000 ____D () C:\zoek_backup
2014-08-08 22:46 - 2014-03-30 15:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-08 22:26 - 2014-08-08 22:26 - 00000049 _____ () C:\Windows\SysWOW64\ScrRecX.log
2014-08-08 22:26 - 2014-02-05 21:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2014-08-08 22:03 - 2014-06-06 19:19 - 00000000 ____D () C:\Users\Denis\Desktop\celtic
2014-08-07 04:06 - 2014-08-14 07:21 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-08-07 04:01 - 2014-08-14 07:21 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-08-06 16:51 - 2014-08-06 16:47 - 00000000 ____D () C:\Users\Denis\Downloads\NeoDownloader
2014-08-06 16:47 - 2014-08-06 16:47 - 00001108 _____ () C:\Users\Denis\Desktop\NeoDownloader Lite.lnk
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\Users\Denis\AppData\Roaming\NeoDownloader
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoDownloader Lite
2014-08-06 16:47 - 2014-08-06 16:47 - 00000000 ____D () C:\Program Files (x86)\NeoDownloader Lite
2014-08-06 16:47 - 2014-08-06 16:46 - 04283816 _____ (Neowise Software ) C:\Users\Denis\Downloads\NeoDownloaderLiteSetup.exe
2014-08-06 11:23 - 2014-08-06 11:23 - 00217954 _____ () C:\Users\Denis\Downloads\[kickass.to]lynda.wordpress.collection.of.40.courses.2010.2014.torrent
2014-08-06 10:59 - 2014-08-06 10:55 - 00003704 _____ () C:\Windows\System32\Tasks\AutoPico Daily Restart
2014-08-06 10:59 - 2014-08-06 10:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico
2014-08-06 10:59 - 2014-08-06 10:55 - 00000000 ____D () C:\Program Files\KMSpico
2014-08-06 10:59 - 2014-02-03 20:42 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-08-06 10:55 - 2014-02-03 20:40 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-08-06 10:50 - 2014-08-06 10:50 - 00004424 _____ () C:\Users\Denis\Downloads\[kickass.to]kms.activator.office.2014.13.all.editions.windows.8.1.8.7.activator.kmspico.9.2.2.rc.simple.easy.torrent
2014-08-06 10:50 - 2014-08-06 10:50 - 00000000 ____D () C:\Users\Denis\Downloads\Microsoft Office Windows Activator(KMSpico 9.2.2 RC)
2014-08-06 10:46 - 2014-08-06 10:51 - 00151552 _____ () C:\Windows\KMService.exe
2014-08-06 10:46 - 2014-08-06 10:51 - 00008192 _____ () C:\Windows\SysWOW64\srvany.exe
2014-08-06 10:40 - 2014-08-06 10:40 - 00000000 ____D () C:\Users\Denis\Documents\Vlastní šablony Office
2014-08-06 09:17 - 2014-08-06 09:14 - 346186209 _____ () C:\Users\Denis\Downloads\Mrtví a neklidní CZ - Warm Bodies (2013).mp4
2014-08-06 03:53 - 2014-02-12 00:30 - 00000000 ____D () C:\Users\Denis\AppData\Local\NVIDIA Corporation
2014-08-06 03:31 - 2014-08-06 03:29 - 00002565 _____ () C:\Windows\diagwrn.xml
2014-08-06 03:31 - 2014-08-06 03:29 - 00001908 _____ () C:\Windows\diagerr.xml
2014-08-06 03:29 - 2009-07-14 06:51 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-06 03:20 - 2014-05-07 03:37 - 00000000 ____D () C:\Users\Denis\AppData\Local\TSVNCache
2014-08-06 03:16 - 2014-08-06 03:16 - 00000045 _____ () C:\Users\Denis\Downloads\microsoft-office-2013-plna-verze-cz-zdarma---odkaz-ke-stažení.txt
2014-08-06 03:15 - 2014-08-06 03:15 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-08-06 03:14 - 2014-08-06 03:14 - 00043256 _____ () C:\Windows\Logo.bmp
2014-08-06 03:14 - 2014-08-06 03:13 - 00000000 ____D () C:\Windows\Activator
2014-08-05 09:20 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-08-04 18:16 - 2014-06-23 11:53 - 00000000 ____D () C:\Users\Denis\Desktop\marcela-viyitka
2014-08-04 10:00 - 2014-08-04 09:54 - 934185872 _____ () C:\Users\Denis\Downloads\District 9(Sektor 9)_CZ dab.(akční,sci-fi,thriler,novinky).avi
2014-08-04 06:07 - 2014-08-04 05:54 - 2088705096 _____ () C:\Users\Denis\Downloads\Need for Speed (2014) HD 720p CZ dabing.avi
2014-08-04 05:53 - 2014-08-04 05:47 - 727287617 _____ () C:\Users\Denis\Downloads\Kronika Temna (Chronicles Of Riddick) 2004 (CZ DAB).avi
2014-08-04 05:50 - 2014-08-04 05:43 - 839389184 _____ () C:\Users\Denis\Downloads\Riddick 1 Černo černá tma - 2000 cz dab.n@y.avi
2014-08-03 23:52 - 2014-08-03 23:51 - 03006258 _____ () C:\Users\Denis\Downloads\freemorphing21.zip
2014-08-03 01:39 - 2014-08-03 01:28 - 1793675264 _____ () C:\Users\Denis\Downloads\Světová válka Z World War Z (2013) CZdub.avi
2014-08-03 01:24 - 2014-08-03 01:19 - 784441344 _____ () C:\Users\Denis\Downloads\Riddick (2013) CZ-Dabing NOVINKA.avi

Some content of TEMP:
====================
C:\Users\Denis\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpi4rhco.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-08-27 01:31

==================== End Of Log ============================

V priloze pridavam

Re: Pomoc se zavirovanem PC

Napsal: 04 zář 2014 18:09
od vyosek
:arrow: Odinstalujte Spybot - Search & Destroy - program ma uz nejlepsi leta davno za sebou a posledni cca 3 roky neni schopen celit aktualnim hrozbam

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472992 2013-03-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41336 2014-05-08] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840568 2014-05-08] (Adobe Systems Inc.)
    HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [54576 2009-11-18] (Hewlett-Packard)
    HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
    HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
    HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [AdobeBridge] => [X]
    HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
    HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [HDDtoGOLaunch] => C:\Users\Denis\AppData\Roaming\CoSoSys\HDDtoGO\HDDtoGOLaunch.exe [172032 2013-09-16] ()
    HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\Run: [Google Update] => C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2014-07-07] (Google Inc.)
    HKU\S-1-5-21-901014225-1187277305-3373686348-1000\...\MountPoints2: {fc804f7a-8fc4-11e3-a7dc-f46d0444b06f} - G:\setup.exe
    
    GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
    
    SearchScopes: HKLM-x32 - DefaultScope value is missing.
    BHO: NNEwSaveR -> {B615577B-A6A1-6893-B28E-716D03686BE6} -> C:\ProgramData\NNEwSaveR\FtG85Y.x64.dll No File
    Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
    Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    
    CHR HomePage: Default -> hxxp://www.trovigo.com/?gd=&ctid=CT3314 ... D42C&SSPV=
    CHR StartupUrls: Default -> "chrome://apps/", "hxxp://google.com/", "hxxp://websearch.fastosearch.info/?pid=1908&r=2014/06/10&hid=7166647310572169449&lg=EN&cc=CZ&unqvl=55", "hxxp://search.gboxapp.com/"
    CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
    
    S2 KMSServerService; C:\Users\Denis\AppData\Local\Temp\BA7.tmp\KMSServerService.exe [X]
    S2 TunMirror; "C:\Users\Denis\AppData\Local\Temp\BA7.tmp\TunMirror.exe" [X]
    
    2014-09-02 08:50 - 2014-09-02 08:51 - 00036750 _____ () C:\Users\Denis\Desktop\FRST.txt
    2014-09-02 08:50 - 2014-09-02 08:50 - 00015327 _____ () C:\Users\Denis\Desktop\LM.bat
    2014-09-02 08:49 - 2014-09-02 08:50 - 00029696 _____ () C:\Users\Denis\AppData\Local\MSGBOX.EXE
    2014-09-02 08:47 - 2014-09-02 08:48 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Desktop\FRSTLauncher (1).exe
    2014-09-02 08:47 - 2014-09-02 08:47 - 00112640 _____ (forum.viry.cz) C:\Users\Denis\Downloads\FRSTLauncher.exe
    2014-08-06 10:50 - 2014-08-06 10:50 - 00000000 ____D () C:\Users\Denis\Downloads\Microsoft Office Windows Activator(KMSpico 9.2.2 RC)
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000Core.job => C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-901014225-1187277305-3373686348-1000UA.job => C:\Users\Denis\AppData\Local\Google\Update\GoogleUpdate.exe
    
    C:\Windows\KMService.exe
    C:\Windows\SysWOW64\srvany.exe
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Pomoc se zavirovanem PC

Napsal: 06 zář 2014 21:22
od Lord-Diablo
Nepochopil jsem ten bod: Presunte vytvoreny fixlist vedle FRST