Stránka 1 z 2

Kontrola logu / pomoc

Napsal: 29 črc 2014 18:06
od GoStyler
Zdravím,
Jistá osoba mi prý dala do pc sledovací program a mě se nelíbí že nemám soukromý na mým vlastním pc......
Přikládám log a prosím kontrolu :)



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:55:50, on 29.7.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17207)
Boot mode: Normal

Running processes:
C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe
C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
C:\Windows\SysWOW64\ctfmon.exe
C:\Program Files (x86)\Gaming Keyboard\OSD.exe
C:\Users\Pavel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pavel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pavel\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Pavel\AppData\Local\Google\Chrome\Application\chrome.exe
D:\Stažené soubory\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:13871
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: ValueApps Loader - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll
O2 - BHO: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [NtVdmSrv] C:\Windows\inf\ntvdm.vbe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [VICTORY Gaming Keyboard] "C:\Program Files (x86)\Gaming Keyboard\Monitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\RunOnce: [GBTUpd] C:\Program Files (x86)\GIGABYTE\UpdManager\PreRun.exe
O4 - HKLM\..\RunOnce: [EasyTuneVI] C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe"  -q
O4 - HKCU\..\Run: [AVG-Secure-Search-Update_0214c] C:\Users\Pavel\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=1ed6c735a2c147d2af244597c6cb586b-b00445ead46b0ebe0415ff39fe8d78ccbc9ff932 /CMPID=0214c
O4 - HKCU\..\Run: [Facebook Update] "C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - Global Startup: GIGABYTE OC_GURU.lnk = C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
O4 - Global Startup: HD Writer.lnk = C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Převést cíl vazby do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Převést cíl vazby do existujícího PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Převést do Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Přidat do stávajícího PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\SysWOW64\bgsvcgen.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: Torch Crash Handler (TorchCrashHandler) - TorchMedia Inc. - C:\Users\Pavel\AppData\Local\Torch\Update\TorchCrashHandler.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update SecretSauce - Unknown owner - C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe
O23 - Service: Util SecretSauce - Unknown owner - C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater18.1.7 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13819 bytes

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 18:20
od Rudy
Zdravím!
Zkusíme tento postup: http://forum.viry.cz/viewtopic.php?f=13&t=133100 .

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 18:33
od GoStyler
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by Pavel (administrator) on PAVELCOMP on 29-07-2014 19:30:07
Running from C:\Users\Pavel\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(TorchMedia Inc.) C:\Users\Pavel\AppData\Local\Torch\Update\TorchCrashHandler.exe
() C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe
() C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SmartRecovery2_x64\RPMDaemon.exe
() C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe
(Panasonic Corporation) C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
(Adobe Systems Incorporated) D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
(Adobe Systems Inc.) D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe
(forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NtVdmSrv] => C:\Windows\inf\ntvdm.vbe [884 2013-06-14] ()
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
HKLM-x32\...\Run: [VICTORY Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [270336 2013-04-09] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2567192 2014-06-02] ()
HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM\...\RunOnce: [RPMKickstart] => C:\Program Files\GIGABYTE\SmartRecovery2_x64\RPMKickstart.exe [2422272 2012-09-06] (Gigabyte Technology CO., LTD.)
HKLM-x32\...\RunOnce: [GBTUpd] => C:\Program Files (x86)\GIGABYTE\UpdManager\PreRun.exe [297480 2008-04-03] (PreRun)
HKLM-x32\...\RunOnce: [EasyTuneVI] => C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [40960 2014-04-02] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [Google Update] => C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-24] (Google Inc.)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [AVG-Secure-Search-Update_0214c] => C:\Users\Pavel\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=1e (the data entry has 85 more characters).
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [Facebook Update] => C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-03-03] (Facebook Inc.)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\MountPoints2: {7499d181-6cc1-11e3-8c9e-94de802fb198} - G:\autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk
ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HD Writer.lnk
ShortcutTarget: HD Writer.lnk -> C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe (Panasonic Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: http=127.0.0.1:13871
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
SearchScopes: HKCU - DefaultScope {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = http://search.conduit.com/Results.aspx? ... rms}&SSPV=
SearchScopes: HKCU - {060076E7-50D3-4229-9873-5C113D237CE2} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {3521FCCA-93F8-46B8-A8B1-CF20F0E27EEF} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {3EF3609F-27C1-4196-A592-F5710B302668} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {5E659612-F3BB-4E46-8DB7-2D3B5D41589C} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {6488D59C-A815-492F-B4F7-CA1CEAF84FB7} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {86ED2674-FBCB-4C1B-B6A5-227D4534F97A} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {92B8BD66-4AC7-4BEF-AB18-05D3A5368E22} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={C06 ... 2014-02-08 18:23:10&v=17.3.1.204&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {97312C7B-4967-4B99-8BB0-ED1BA49FC486} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {B08A6BCF-6D2A-467B-B23F-3F66A9B11C22} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {BF14B370-C886-446E-93B8-CD2B86C80740} URL = http://search.us.com/serp?guid={3D40BAF ... earchTerms}
SearchScopes: HKCU - {DBBF9D1F-9263-4D90-9DF8-40C313A427EA} URL = http://search.yahoo.com/search?p={searc ... type=10511
BHO: HDvid Codec V6.0 -> {11111111-1111-1111-1111-110411591171} -> C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-bho64.dll (installdaddy)
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: ValueApps -> {93DBF2BB-A2B3-4683-A92E-57E60751F346} -> C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: ValueApps -> {93DBF2BB-A2B3-4683-A92E-57E60751F346} -> C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
BHO-x32: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: 127.0.0.1 activate.adobe.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pavel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Pavel\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Pavel\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Pavel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.1.204
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.1.204 [2014-02-08]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "hxxp://mysearch.avg.com?cid={C06CA908-199B-4CC8-AC42-A1E5D82B60FA}&mid=1ed6c735a2c147d2af244597c6cb586b-b00445ead46b0ebe0415ff39fe8d78ccbc9ff932&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-08 18:23:10&v=18.1.5.512&pid=safeguard&sg=&sap=hp"
CHR Extension: (Dokumenty Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-24]
CHR Extension: (Disk Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-24]
CHR Extension: (YouTube) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-24]
CHR Extension: (Battlefield Heroes) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-12-30]
CHR Extension: (Vyhledávání Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-24]
CHR Extension: (AdBlock) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-27]
CHR Extension: (Red Alien) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlklddbgohcheiaiidjodbnlfcipcdeo [2014-06-01]
CHR Extension: (AVG SafeGuard) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-05-03]
CHR Extension: (Peněženka Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-24]
CHR Extension: (Gmail) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-24]
CHR Extension: (Managera) - C:\Users\Pavel\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42 [2013-12-29]
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Pavel\AppData\Local\Torch\Plugins\TorchPlugin.crx [2014-01-01]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2014-04-02] (Macrovision Corporation) [File not signed]
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-07-12] ()
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2014-06-01] (Microsoft Corporation) [File not signed]
R2 TorchCrashHandler; C:\Users\Pavel\AppData\Local\Torch\Update\TorchCrashHandler.exe [1206624 2013-07-20] (TorchMedia Inc.) [File not signed]
S3 TunngleService; D:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
R2 Update SecretSauce; C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe [321824 2014-07-25] ()
R2 Util SecretSauce; C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe [321824 2014-07-25] ()
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1808408 2014-06-02] (AVG Secure Search)
S4 BlockAndSurf; C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfiQ161.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AODDriver; C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22128 2012-03-08] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-02] (AVG Technologies)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-24] (Disc Soft Ltd)
R3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-07-29] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-29 19:30 - 2014-07-29 19:30 - 00023505 _____ () C:\Users\Pavel\Desktop\FRST.txt
2014-07-29 19:29 - 2014-07-29 19:30 - 00000000 ____D () C:\FRST
2014-07-29 19:29 - 2014-07-29 19:28 - 00112640 _____ (forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
2014-07-29 19:29 - 2014-07-29 19:27 - 02093568 _____ (Farbar) C:\Users\Pavel\Desktop\FRST64.exe
2014-07-29 11:03 - 2014-07-29 19:27 - 00000004 _____ () C:\Windows\SysWOW64\GVTunner.ref
2014-07-27 11:30 - 2014-07-27 11:30 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 11:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-27 11:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-27 11:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-27 11:14 - 2014-07-27 11:14 - 00000000 ____D () C:\Users\Pavel\.swt
2014-07-22 17:49 - 2014-07-27 10:59 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-07-19 21:27 - 2014-07-19 21:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-07-16 21:23 - 2014-07-16 21:23 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-10 20:25 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 20:25 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 20:25 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 20:25 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 20:25 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 20:25 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 20:25 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 20:25 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 20:25 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 20:25 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 20:25 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 20:25 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 20:25 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 20:25 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 20:25 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 20:25 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 20:25 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 20:25 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 20:25 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 20:25 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 20:25 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 20:25 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 20:25 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 20:25 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 20:25 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 20:25 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 20:25 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 20:25 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 20:25 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 20:25 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 20:25 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 20:25 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 20:25 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 20:25 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 20:25 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 20:25 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 20:25 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 20:25 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 20:25 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 20:25 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 20:25 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 20:25 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 20:25 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 20:25 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 20:25 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 20:25 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 20:25 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 20:25 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 20:25 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 20:25 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 20:25 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 20:25 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 20:25 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 20:25 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 20:25 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 20:25 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 20:25 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 20:25 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 20:25 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 20:25 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 20:25 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 20:25 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 20:24 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 20:24 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 20:24 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free AVCHD Converter
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\Program Files (x86)\Free AVCHD Converter
2014-07-03 20:42 - 2014-07-03 20:42 - 00007600 _____ () C:\Users\Pavel\AppData\Local\Resmon.ResmonCfg
2014-07-03 20:19 - 2014-07-05 20:44 - 00000000 ____D () C:\Users\Pavel\AppData\Local\ftblauncher
2014-07-03 20:19 - 2014-07-03 20:26 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\ftblauncher

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-29 19:30 - 2014-07-29 19:30 - 00023505 _____ () C:\Users\Pavel\Desktop\FRST.txt
2014-07-29 19:30 - 2014-07-29 19:29 - 00000000 ____D () C:\FRST
2014-07-29 19:30 - 2013-12-25 16:45 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-29 19:29 - 2013-12-21 22:13 - 01650167 _____ () C:\Windows\WindowsUpdate.log
2014-07-29 19:28 - 2014-07-29 19:29 - 00112640 _____ (forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
2014-07-29 19:27 - 2014-07-29 19:29 - 02093568 _____ (Farbar) C:\Users\Pavel\Desktop\FRST64.exe
2014-07-29 19:27 - 2014-07-29 11:03 - 00000004 _____ () C:\Windows\SysWOW64\GVTunner.ref
2014-07-29 19:27 - 2013-12-21 22:41 - 00000000 ____D () C:\Users\Pavel\Documents\temp
2014-07-29 19:27 - 2013-12-21 22:40 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-07-29 19:27 - 2013-12-21 22:27 - 00030528 _____ () C:\Windows\GVTDrv64.sys
2014-07-29 19:26 - 2014-05-18 15:01 - 00000424 _____ () C:\Windows\Tasks\BlockAndSurf Update.job
2014-07-29 19:26 - 2014-05-18 15:01 - 00000414 _____ () C:\Windows\Tasks\BlockAndSurf_wd.job
2014-07-29 19:26 - 2014-01-23 12:48 - 00002426 _____ () C:\Windows\Tasks\HDvid Codec V6.0-firefoxinstaller.job
2014-07-29 19:26 - 2014-01-23 12:48 - 00002210 _____ () C:\Windows\Tasks\HDvid Codec V6.0-chromeinstaller.job
2014-07-29 19:26 - 2014-01-23 12:48 - 00001544 _____ () C:\Windows\Tasks\HDvid Codec V6.0-updater.job
2014-07-29 19:26 - 2014-01-23 12:48 - 00001484 _____ () C:\Windows\Tasks\HDvid Codec V6.0-codedownloader.job
2014-07-29 19:26 - 2014-01-23 12:48 - 00001372 _____ () C:\Windows\Tasks\HDvid Codec V6.0-enabler.job
2014-07-29 19:26 - 2014-01-01 20:20 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-07-29 19:26 - 2013-12-25 16:45 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-29 19:26 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-29 19:26 - 2009-07-14 06:51 - 00152829 _____ () C:\Windows\setupact.log
2014-07-29 18:57 - 2009-07-26 20:41 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-07-29 18:57 - 2009-07-26 20:41 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-07-29 18:57 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-29 18:57 - 2009-07-14 06:45 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-29 18:57 - 2009-07-14 06:45 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-29 17:49 - 2013-12-24 19:42 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-29 16:13 - 2013-12-21 23:19 - 00430792 _____ () C:\Windows\PFRO.log
2014-07-29 15:36 - 2014-01-08 18:27 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-29 15:33 - 2014-03-03 19:28 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
2014-07-29 15:20 - 2013-12-24 19:41 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
2014-07-29 11:37 - 2014-01-10 16:24 - 00000000 ____D () C:\Users\Pavel\AppData\Local\PMB Files
2014-07-29 11:08 - 2013-12-24 20:03 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Seznam.cz
2014-07-28 18:33 - 2014-03-03 19:28 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
2014-07-28 11:04 - 2014-03-20 19:34 - 00000000 ___RD () C:\Users\Pavel\Desktop\ 
2014-07-27 11:30 - 2014-07-27 11:30 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 11:29 - 2014-01-10 16:24 - 00000000 ____D () C:\ProgramData\PMB Files
2014-07-27 11:14 - 2014-07-27 11:14 - 00000000 ____D () C:\Users\Pavel\.swt
2014-07-27 11:14 - 2013-12-21 22:10 - 00000000 ____D () C:\Users\Pavel
2014-07-27 10:59 - 2014-07-22 17:49 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-07-25 10:20 - 2013-12-24 19:41 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
2014-07-23 12:44 - 2013-12-24 20:18 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\AIMP3
2014-07-20 19:44 - 2014-01-20 22:43 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-19 21:27 - 2014-07-19 21:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-07-16 21:23 - 2014-07-16 21:23 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-13 10:54 - 2014-01-02 20:33 - 00000000 ____D () C:\ProgramData\Origin
2014-07-12 20:35 - 2013-12-25 11:32 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Skype
2014-07-12 10:31 - 2013-12-30 22:58 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-07-12 10:31 - 2013-12-30 22:54 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-12 10:31 - 2013-12-30 22:54 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-12 10:27 - 2013-12-30 22:54 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-07-11 19:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-11 10:56 - 2009-07-14 06:45 - 03111136 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 10:55 - 2009-07-14 09:46 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 10:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 10:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-11 00:15 - 2013-12-30 17:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-11 00:13 - 2013-12-30 17:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-10 19:31 - 2009-07-14 07:08 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-09 11:36 - 2014-01-08 18:27 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 11:36 - 2014-01-08 18:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 11:36 - 2014-01-08 18:27 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free AVCHD Converter
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\Program Files (x86)\Free AVCHD Converter
2014-07-08 16:54 - 2013-12-24 19:50 - 00000000 ____D () C:\Users\Pavel\Desktop\Programy
2014-07-05 21:56 - 2014-02-01 16:46 - 00000000 ____D () C:\ProgramData\Tunngle
2014-07-05 21:56 - 2014-01-08 16:43 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Tunngle
2014-07-05 20:44 - 2014-07-03 20:19 - 00000000 ____D () C:\Users\Pavel\AppData\Local\ftblauncher
2014-07-03 20:47 - 2013-12-27 19:26 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\.minecraft
2014-07-03 20:42 - 2014-07-03 20:42 - 00007600 _____ () C:\Users\Pavel\AppData\Local\Resmon.ResmonCfg
2014-07-03 20:26 - 2014-07-03 20:19 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\ftblauncher
2014-07-03 10:50 - 2014-03-31 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-01 11:29 - 2014-03-19 19:03 - 00637952 ___SH () C:\Users\Pavel\Desktop\Thumbs.db
2014-06-29 17:21 - 2013-12-24 19:50 - 00000000 ____D () C:\Users\Pavel\Desktop\Hry

Some content of TEMP:
====================
C:\Users\Pavel\AppData\Local\Temp\dlLogic.exe
C:\Users\Pavel\AppData\Local\Temp\ebdkbfyx.3ak.exe
C:\Users\Pavel\AppData\Local\Temp\EnableExtDll.dll
C:\Users\Pavel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Pavel\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-14-g15b04d8-b2991jnks.dll
C:\Users\Pavel\AppData\Local\Temp\KMP_3.8.0.120.exe
C:\Users\Pavel\AppData\Local\Temp\KMP_3.9.0.126.exe
C:\Users\Pavel\AppData\Local\Temp\LAUNCHER__6601_IL4765.EXE
C:\Users\Pavel\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Pavel\AppData\Local\Temp\nsj7F44.exe
C:\Users\Pavel\AppData\Local\Temp\nsj95D2.exe
C:\Users\Pavel\AppData\Local\Temp\nso9380.exe
C:\Users\Pavel\AppData\Local\Temp\nsu7D12.exe
C:\Users\Pavel\AppData\Local\Temp\nsw3508.exe
C:\Users\Pavel\AppData\Local\Temp\SIntf16.dll
C:\Users\Pavel\AppData\Local\Temp\SIntf32.dll
C:\Users\Pavel\AppData\Local\Temp\SIntfNT.dll
C:\Users\Pavel\AppData\Local\Temp\ssins.exe
C:\Users\Pavel\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Pavel\AppData\Local\Temp\Uninstall.exe
C:\Users\Pavel\AppData\Local\Temp\utt5C56.tmp.exe
C:\Users\Pavel\AppData\Local\Temp\war3_Install.exe
C:\Users\Pavel\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Pavel\AppData\Local\Temp\_is63F0.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-28 12:15




===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: (SSD) (Fixed) (Total:119.14 GB) (Free:75.85 GB) NTFS
Drive d: (HDD) (Fixed) (Total:1863.01 GB) (Free:1181.14 GB) NTFS
Drive g: (20101108_2038) (CDROM) (Total:0.39 GB) (Free:0 GB) CDFS

Available physical RAM: 6250.25 MB
Total physical RAM: 8155.52 MB
Percentage of memory in use: 23%

==================== MBR and Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119 GB) (Disk ID: 847D6BC7)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 67FB6853)
Partition 1: (Not Active) - (Size=-198626508800) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\BlockAndSurf Update.job => C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurft55.exe <==== ATTENTION
Task: C:\Windows\Tasks\BlockAndSurf_wd.job => C:\Program Files (x86)\BlockAndSurf-soft\BlockAndSurfgdGIow.exe <==== ATTENTION
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job => C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job => C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job => C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job => C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HDvid Codec V6.0-chromeinstaller.job => C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-chromeinstaller.exe
Task: C:\Windows\Tasks\HDvid Codec V6.0-codedownloader.job => C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-codedownloader.exe
Task: C:\Windows\Tasks\HDvid Codec V6.0-enabler.job => C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-enabler.exe
Task: C:\Windows\Tasks\HDvid Codec V6.0-firefoxinstaller.job => C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-firefoxinstaller.exe
Task: C:\Windows\Tasks\HDvid Codec V6.0-updater.job => C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-updater.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4

==================== Security Center ==================

AV: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2014 (Disabled - Up to date) {B5F5C120-2089-702E-0001-553BB0D5A664}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Pavel\Desktop" je 18 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 18:44
od Rudy
Nejprve se ale zeptám: Jak je na tom váš oper. systém s legalitou?

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 18:54
od GoStyler
Pc jsem zakoupil asi před půl rokem na aukro.cz, takže nevím, protože tam OS už byl :)

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 19:45
od Rudy
Udělejte nejprve kompletní sken MBAM a dejte log. Předem nic nemažte.

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 20:19
od GoStyler
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 29.7.2014
Scan Time: 21:10:56
Logfile: aaa.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.29.05
Rootkit Database: v2014.07.17.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Pavel

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 301592
Time Elapsed: 7 min, 8 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 2
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe, 1936, , [c4857c2995e63df98f77bea0f90816ea]
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe, 2456, , [02475b4ab4c7191d4cbac79757aa4db3]

Modules: 0
(No malicious items detected)

Registry Keys: 49
PUP.Optional.SecretSauce.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update SecretSauce, , [c4857c2995e63df98f77bea0f90816ea],
PUP.Optional.SecretSauce.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util SecretSauce, , [02475b4ab4c7191d4cbac79757aa4db3],
PUP.Optional.HDvidCodec.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411591171}, , [b79244613c3ff640caf340e532cfb050],
PUP.Optional.HDvidCodec.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110411591171}, , [b79244613c3ff640caf340e532cfb050],
PUP.Optional.HDvidCodec.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220422592271}, , [b79244613c3ff640caf340e532cfb050],
PUP.Optional.HDvidCodec.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110411591171}\INPROCSERVER32, , [b79244613c3ff640caf340e532cfb050],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}\INPROCSERVER32, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [6ddc94116417e551f437afe840c2a25e],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, , [6ddc94116417e551f437afe840c2a25e],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{F63AAEDC-3602-49EF-AA45-262380A98980}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F63AAEDC-3602-49EF-AA45-262380A98980}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [b7928322adcebf776c5bc895e121b34d],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{DEDAF650-12B8-48F5-A843-BBA100716106}, , [c386089d9be03006efa8fb690ff3748c],
PUP.Optional.BlockAndSurf.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BlockAndSurf, , [de6b5f468fecec4a33a663858f73619f],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [69e06f36cfacee48f740c04e2ed625db],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [87c2a4011a61072fe9536bb629dbda26],
PUP.Optional.HDvidCodec.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HDvid Codec V6.0, , [00490d986d0e0b2b4ee27f739969ee12],
PUP.Optional.ValueApps.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueApps, , [e168f9ac403bb97d00384cab7e84946c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\installdaddy, , [69e0416481fa68ce10babc5181834bb5],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [d574e4c11c5f39fd8657865f34ce1fe1],
PUP.Optional.HDVidCodec.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HDvid Codec V6.0, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\1ClickDownload, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.ValueAppsplugin.A, HKU\S-1-5-21-1461227209-3297222852-4237083345-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ValueApps, , [80c98421e39852e4e265e0ccdd25b24e],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{DD7858C7-889A-42E4-9863-E4AA3A0BFE65}, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{68FD483F-A55D-4B78-AE10-48EF2BBE317E}, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{DEBFDDD0-96AA-400F-B77A-69003A94018B}, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{68FD483F-A55D-4B78-AE10-48EF2BBE317E}, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DEBFDDD0-96AA-400F-B77A-69003A94018B}, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DD7858C7-889A-42E4-9863-E4AA3A0BFE65}, , [3316fca981fa1d192821c6e6877bfe02],

Registry Values: 1
Malware.Trace, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NtVdmSrv, C:\Windows\inf\ntvdm.vbe, , [e9601293b1ca93a3cd497698996bb54b]

Registry Data: 0
(No malicious items detected)

Folders: 18
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce, , [71d8ddc8fc7f59dd635838e34cb8bb45],
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\bin, , [71d8ddc8fc7f59dd635838e34cb8bb45],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\ct3311333, , [1633abfa1368fc3a03ce0e9c5aa88878],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\CT3317212, , [6bdef1b42556e3531bb67a3051b153ad],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\CT3319597, , [8dbc1f86b5c677bff3de545608faff01],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.NextLive.A, C:\Users\Pavel\AppData\Roaming\newnext.me, , [9bae277e641796a08088ddcfa260e818],
PUP.Optional.NextLive.A, C:\Users\Pavel\AppData\Roaming\newnext.me\cache, , [9bae277e641796a08088ddcfa260e818],
PUP.Optional.ValueAppsplugin.A, C:\Program Files\Conduit\ValueApps, , [34158223295258ded2753775976b49b7],
PUP.Optional.ValueAppsplugin.A, C:\Program Files\Conduit\ValueApps\IE, , [34158223295258ded2753775976b49b7],
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps, , [80c98421e39852e4e265e0ccdd25b24e],
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE, , [80c98421e39852e4e265e0ccdd25b24e],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\64, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\mam-ct3317212, , [15347b2a215a5ed81a8ef8b852b0c937],
PUP.Optional.Managera.A, C:\Users\Pavel\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, , [a2a72f764833ca6c8d083a88877b02fe],

Files: 83
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\updateSecretSauce.exe, , [c4857c2995e63df98f77bea0f90816ea],
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.exe, , [02475b4ab4c7191d4cbac79757aa4db3],
PUP.Optional.HDvidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-bho64.dll, , [b79244613c3ff640caf340e532cfb050],
PUP.Optional.ValueApps.A, C:\Program Files\Conduit\ValueApps\IE\ValueAppsLoader.dll, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll, , [a2a7e5c0106b49edc0db27241ae7b64a],
PUP.Optional.ValueApps.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\64\MonPrx.dll, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.ValueApps.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\MonPrx.dll, , [4ffac7de5d1ed85e227d4122778beb15],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\dlLogic.exe, , [7acf9c0998e3e55150e1947c38c901ff],
PUP.Optional.Softonic.A, C:\Users\Pavel\AppData\Local\Temp\KMP_3.8.0.120.exe, , [ec5dfea74f2ce94d0030052429d80ff1],
PUP.Optional.SearchProtect.A, C:\Users\Pavel\AppData\Local\Temp\nsu7D12.exe, , [76d37233ff7cb6800e70de5408f9ba46],
PUP.Optional.SearchProtect.A, C:\Users\Pavel\AppData\Local\Temp\nsw3508.exe, , [ff4a9411fa812511e19d2d053cc5cd33],
PUP.Optional.SearchProtect.A, C:\Users\Pavel\AppData\Local\Temp\nsj7F44.exe, , [34158421a4d77db97905042e47ba33cd],
PUP.Optional.SearchProtect.A, C:\Users\Pavel\AppData\Local\Temp\nsj95D2.exe, , [de6b04a1334836001866c072fb069e62],
PUP.Optional.SearchProtect.A, C:\Users\Pavel\AppData\Local\Temp\nso9380.exe, , [43066a3b8af1d264e09ec46eff0242be],
PUP.Optional.Pcoptimzer, C:\Users\Pavel\AppData\Local\Temp\awhAB38.tmp, , [2b1ebaeb97e40135b631afd5e81c39c7],
PUP.Optional.Somoto, C:\Users\Pavel\AppData\Local\Temp\nsaD176.tmp, , [cc7d1a8b81fa6fc71bbc4df0b64e3ac6],
PUP.Optional.Conduit, C:\Users\Pavel\AppData\Local\Temp\mam-ct3317212\ctbe.exe, , [1a2fd9cc4b30d264ba3f9292b947d12f],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\mam-ct3317212\mamstub.exe, , [ee5b287df388fb3b8ea313fdf60bb54b],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\mam-ct3317212\mam_ch.exe, , [2b1e6e371d5ede583b92c77bdd2321df],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\mam-ct3317212\mam_ie.exe, , [b3967134f08bbe7865f80e64b948c53b],
PUP.Optional.OptimumInstaller.A, C:\Users\Pavel\AppData\Local\Temp\nsgE793.tmp\SevenZip_Setup.exe, , [54f58f165c1f50e66865db7b1ae7fa06],
PUP.Optional.OpenCandy, C:\Users\Pavel\AppData\Local\Temp\nspBDB5.tmp\DTLite.exe, , [0e3bb8edcdae4aec4d74b5287a8adb25],
PUP.Optional.BlockAndSurf.A, C:\Windows\System32\Tasks\BlockAndSurf Update, , [e564b9ec9be058def95b4b8937cb54ac],
PUP.Optional.BlockAndSurf.A, C:\Windows\System32\Tasks\BlockAndSurf_wd, , [cd7c960f9be0f83e82d36371e31ffc04],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage, , [ac9d4362d5a668ce89d919c55da533cd],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_app.mam.conduit.com_0.localstorage-journal, , [4dfc0e97413ad3633230e3fb7f833dc3],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage, , [28218a1bb0cbd462046016c849b952ae],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_storage.conduit.com_0.localstorage-journal, , [0d3c3174b7c413237ce8b42a43bfda26],
PUP.Optional.Superfish.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, , [f455edb8f18a4cea486eb82603ffc13f],
PUP.Optional.Superfish.A, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, , [fb4e7c2984f76fc70aac409ee61cee12],
PUP.Optional.BlockAndSurf.A, C:\Windows\Tasks\BlockAndSurf Update.job, , [e960366fb0cb41f55d7a03e59a6809f7],
PUP.Optional.BlockAndSurf.A, C:\Windows\Tasks\BlockAndSurf_wd.job, , [86c3faab0f6c1a1c0ec904e444bee11f],
PUP.Optional.Pricegong, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage, , [9aaf901557247db9b07228cd778b49b7],
PUP.Optional.Pricegong, C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pricegong.conduitapps.com_0.localstorage-journal, , [c287ccd9f08bd462839ff8fd9d65cf31],
Malware.Trace, C:\Windows\inf\ntvdm.vbe, , [e9601293b1ca93a3cd497698996bb54b],
Malware.Trace, C:\Windows\inf\ntvdm.inf, , [7acfefb67308c571c75057b7c73dae52],
PUP.Optional.HDVidCodec.A, C:\Windows\Tasks\HDvid Codec V6.0-chromeinstaller.job, , [23269411f883be7807a8e338e81c6e92],
PUP.Optional.HDVidCodec.A, C:\Windows\Tasks\HDvid Codec V6.0-codedownloader.job, , [9faa0d9897e4d75fe1ce001b57adc739],
PUP.Optional.HDVidCodec.A, C:\Windows\Tasks\HDvid Codec V6.0-enabler.job, , [dd6c525358231e18228d011a798b28d8],
PUP.Optional.HDVidCodec.A, C:\Windows\Tasks\HDvid Codec V6.0-firefoxinstaller.job, , [0841198c0a71989e7f301dfe3ec64eb2],
PUP.Optional.HDVidCodec.A, C:\Windows\Tasks\HDvid Codec V6.0-updater.job, , [fa4fd2d36d0e92a4931ccc4fd33104fc],
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\SecretSauce.ico, , [71d8ddc8fc7f59dd635838e34cb8bb45],
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\updateSecretSauce.InstallState, , [71d8ddc8fc7f59dd635838e34cb8bb45],
PUP.Optional.SecretSauce.A, C:\Program Files (x86)\SecretSauce\bin\utilSecretSauce.InstallState, , [71d8ddc8fc7f59dd635838e34cb8bb45],
PUP.Optional.HDvidCodec.A, C:\Windows\System32\Tasks\HDvid Codec V6.0-chromeinstaller, , [c485b4f1255620163a975ad4ec189868],
PUP.Optional.HDvidCodec.A, C:\Windows\System32\Tasks\HDvid Codec V6.0-codedownloader, , [ac9d90150e6d2c0a04cd2b033dc71ce4],
PUP.Optional.HDvidCodec.A, C:\Windows\System32\Tasks\HDvid Codec V6.0-enabler, , [0b3e772ee299ea4cba1740ee887ca060],
PUP.Optional.HDvidCodec.A, C:\Windows\System32\Tasks\HDvid Codec V6.0-firefoxinstaller, , [1d2c495c522956e0a13055d921e3bb45],
PUP.Optional.HDvidCodec.A, C:\Windows\System32\Tasks\HDvid Codec V6.0-updater, , [4009a5009eddb680e5ec65c9e91b9a66],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\ct3311333\chromeid.txt, , [1633abfa1368fc3a03ce0e9c5aa88878],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\ct3311333\setup.ini.txt, , [1633abfa1368fc3a03ce0e9c5aa88878],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\CT3317212\ddt.csf, , [6bdef1b42556e3531bb67a3051b153ad],
PUP.Optional.Conduit.A, C:\Users\Pavel\AppData\Local\Temp\CT3319597\ddt.csf, , [8dbc1f86b5c677bff3de545608faff01],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-buttonutil64.exe, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\45971.crx, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\45971.xpi, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\background.html, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-buttonutil.dll, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-buttonutil64.dll, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0-helper.exe, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\HDvid Codec V6.0.ico, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\Installer.log, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\Uninstall.exe, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\HDvid Codec V6.0\utils.exe, , [9aaff3b2562544f2c8007635b052817f],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\b.bmp, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\finish.bmp, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\FinishHDVID.exe, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\HDVidCodec.exe, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\hdvidextsetup.exe, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\hdvid_temp.bmp, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\stage2, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.HDVidCodec.A, C:\Program Files (x86)\hdvidcodec.com\uninst.exe, , [9eabd8cd93e837ffa5242f7ce71ba55b],
PUP.Optional.NextLive.A, C:\Users\Pavel\AppData\Roaming\newnext.me\nengine.cookie, , [9bae277e641796a08088ddcfa260e818],
PUP.Optional.NextLive.A, C:\Users\Pavel\AppData\Roaming\newnext.me\cache\spark.bin, , [9bae277e641796a08088ddcfa260e818],
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE\uninstaller.exe, , [80c98421e39852e4e265e0ccdd25b24e],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\MonPrx.dll_old, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\settings.json, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\ValueApps.exe, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\64\settings.json, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\64\ValueApps.exe, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.ValueAppsplugin.A, C:\Users\Pavel\AppData\Local\Conduit\ValueApps\IE\64\ValueApps.exe_old, , [3316fca981fa1d192821c6e6877bfe02],
PUP.Optional.Managera.A, C:\Users\Pavel\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, , [a2a72f764833ca6c8d083a88877b02fe],
PUP.Optional.Managera.A, C:\Users\Pavel\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, , [a2a72f764833ca6c8d083a88877b02fe],

Physical Sectors: 0
(No malicious items detected)


(end)

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 21:11
od Rudy
Vše nalezené smažte a dejte nový log FRST.

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 21:27
od GoStyler
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014
Ran by Pavel (administrator) on PAVELCOMP on 29-07-2014 22:26:29
Running from C:\Users\Pavel\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(B.H.A Corporation) C:\Windows\SysWOW64\bgsvcgen.exe
(Malwarebytes Corporation) D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(TorchMedia Inc.) C:\Users\Pavel\AppData\Local\Torch\Update\TorchCrashHandler.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\loggingserver.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(Gigabyte Technology CO.) C:\Program Files\GIGABYTE\SmartRecovery2_x64\RPMDaemon.exe
() C:\Program Files (x86)\GIGABYTE\ET6\GUI.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe
(Panasonic Corporation) C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Program Files (x86)\Gaming Keyboard\Monitor.EXE
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe
() C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
(Adobe Systems Incorporated) D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
(Adobe Systems Inc.) D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
() C:\Program Files (x86)\Gaming Keyboard\OSD.exe
(forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(PandoraTV) C:\Program Files (x86)\PANDORA.TV\PanService\KMPProcess.exe
(Microsoft Corporation) C:\Windows\SysWOW64\PING.EXE


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5263504 2012-08-09] (VIA)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5179408 2014-06-17] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
HKLM-x32\...\Run: [VICTORY Gaming Keyboard] => C:\Program Files (x86)\Gaming Keyboard\Monitor.exe [270336 2013-04-09] ()
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe [2567192 2014-06-02] ()
HKLM-x32\...\Run: [AdobeCS4ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [611712 2008-08-14] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [37232 2008-06-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => D:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.)
HKLM\...\RunOnce: [RPMKickstart] => C:\Program Files\GIGABYTE\SmartRecovery2_x64\RPMKickstart.exe [2422272 2012-09-06] (Gigabyte Technology CO., LTD.)
HKLM-x32\...\RunOnce: [GBTUpd] => C:\Program Files (x86)\GIGABYTE\UpdManager\PreRun.exe [297480 2008-04-03] (PreRun)
HKLM-x32\...\RunOnce: [EasyTuneVI] => C:\Program Files (x86)\GIGABYTE\ET6\ETCall.exe [40960 2014-04-02] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [Google Update] => C:\Users\Pavel\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-12-24] (Google Inc.)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Pavel\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [AVG-Secure-Search-Update_0214c] => C:\Users\Pavel\AppData\Roaming\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=1e (the data entry has 85 more characters).
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\Run: [Facebook Update] => C:\Users\Pavel\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-03-03] (Facebook Inc.)
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\MountPoints2: {7499d181-6cc1-11e3-8c9e-94de802fb198} - G:\autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE OC_GURU.lnk
ShortcutTarget: GIGABYTE OC_GURU.lnk -> C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe (GIGABYTE Technology Co.,Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HD Writer.lnk
ShortcutTarget: HD Writer.lnk -> C:\Program Files (x86)\Common Files\Panasonic\HD Writer AutoStart\HDWriterAutoStart.exe (Panasonic Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: http=127.0.0.1:13871
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
SearchScopes: HKCU - DefaultScope {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {060076E7-50D3-4229-9873-5C113D237CE2} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {3521FCCA-93F8-46B8-A8B1-CF20F0E27EEF} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {3EF3609F-27C1-4196-A592-F5710B302668} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {5E659612-F3BB-4E46-8DB7-2D3B5D41589C} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {6488D59C-A815-492F-B4F7-CA1CEAF84FB7} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {86ED2674-FBCB-4C1B-B6A5-227D4534F97A} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {92B8BD66-4AC7-4BEF-AB18-05D3A5368E22} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={C06 ... 2014-02-08 18:23:10&v=17.3.1.204&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {97312C7B-4967-4B99-8BB0-ED1BA49FC486} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {B08A6BCF-6D2A-467B-B23F-3F66A9B11C22} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {BF14B370-C886-446E-93B8-CD2B86C80740} URL = http://search.us.com/serp?guid={3D40BAF ... earchTerms}
SearchScopes: HKCU - {DBBF9D1F-9263-4D90-9DF8-40C313A427EA} URL = http://search.yahoo.com/search?p={searc ... type=10511
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: AVG SafeGuard toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - AVG SafeGuard toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG SafeGuard toolbar\18.1.7.598\AVG SafeGuard toolbar_toolbar.dll (AVG Secure Search)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\18.1.7\ViProtocol.dll (AVG Secure Search)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
Hosts: 127.0.0.1 activate.adobe.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File
FF Plugin: @java.com/JavaPlugin,version=10.9.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 - C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pavel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Pavel\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Pavel\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Pavel\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.1.204
FF Extension: AVG SafeGuard toolbar - C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.3.1.204 [2014-02-08]

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR StartupUrls: "hxxp://mysearch.avg.com?cid={C06CA908-199B-4CC8-AC42-A1E5D82B60FA}&mid=1ed6c735a2c147d2af244597c6cb586b-b00445ead46b0ebe0415ff39fe8d78ccbc9ff932&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-08 18:23:10&v=18.1.5.512&pid=safeguard&sg=&sap=hp"
CHR Extension: (Dokumenty Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-24]
CHR Extension: (Disk Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-24]
CHR Extension: (YouTube) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-24]
CHR Extension: (Battlefield Heroes) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-12-30]
CHR Extension: (Vyhledávání Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-24]
CHR Extension: (AdBlock) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-27]
CHR Extension: (Red Alien) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlklddbgohcheiaiidjodbnlfcipcdeo [2014-06-01]
CHR Extension: (AVG SafeGuard) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-05-03]
CHR Extension: (Peněženka Google) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-24]
CHR Extension: (Gmail) - C:\Users\Pavel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-24]
CHR HKLM-x32\...\Chrome\Extension: [kiplfnciaokpcennlkldkdaeaaomamof] - C:\Users\Pavel\AppData\Local\Torch\Plugins\TorchPlugin.crx [2014-01-01]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) [File not signed]
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3241488 2014-06-27] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [160256 2011-08-30] (Intel Corporation) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2014-04-02] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-07-12] ()
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2014-06-01] (Microsoft Corporation) [File not signed]
R2 TorchCrashHandler; C:\Users\Pavel\AppData\Local\Torch\Update\TorchCrashHandler.exe [1206624 2013-07-20] (TorchMedia Inc.) [File not signed]
S3 TunngleService; D:\Program Files (x86)\Tunngle\TnglCtrl.exe [758224 2013-11-06] (Tunngle.net GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-03] (VIA Technologies, Inc.)
R2 vToolbarUpdater18.1.7; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.7\ToolbarUpdater.exe [1808408 2014-06-02] (AVG Secure Search)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 AODDriver; C:\Program Files (x86)\GIGABYTE\ET6\amd64\AODDriver.sys [52280 2010-03-12] (Advanced Micro Devices)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [53888 2012-03-05] (Advanced Micro Devices)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [22128 2012-03-08] ()
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [242968 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-06-02] (AVG Technologies)
R1 cdrbsdrv; C:\Windows\System32\Drivers\cdrbsdrv.sys [39208 2006-08-25] (B.H.A Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-24] (Disc Soft Ltd)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
R3 GVTDrv64; C:\Windows\GVTDrv64.sys [30528 2014-07-29] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-29 22:26 - 2014-07-29 22:26 - 00029696 _____ () C:\Users\Pavel\AppData\Local\MSGBOX.EXE
2014-07-29 22:26 - 2014-07-29 22:26 - 00022833 _____ () C:\Users\Pavel\Desktop\FRST.txt
2014-07-29 22:26 - 2014-07-29 22:26 - 00015327 _____ () C:\Users\Pavel\Desktop\LM.bat
2014-07-29 21:09 - 2014-07-29 22:15 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-29 21:09 - 2014-07-29 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-29 21:09 - 2014-07-29 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-29 21:09 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-29 21:09 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-29 21:09 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-29 19:29 - 2014-07-29 22:26 - 00000000 ____D () C:\FRST
2014-07-29 19:29 - 2014-07-29 19:28 - 00112640 _____ (forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
2014-07-29 19:29 - 2014-07-29 19:27 - 02093568 _____ (Farbar) C:\Users\Pavel\Desktop\FRST64.exe
2014-07-29 11:03 - 2014-07-29 22:25 - 00000004 _____ () C:\Windows\SysWOW64\GVTunner.ref
2014-07-27 11:30 - 2014-07-27 11:30 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 11:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-27 11:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-27 11:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-27 11:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-27 11:14 - 2014-07-27 11:14 - 00000000 ____D () C:\Users\Pavel\.swt
2014-07-22 17:49 - 2014-07-27 10:59 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-07-19 21:27 - 2014-07-19 21:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-07-16 21:23 - 2014-07-16 21:23 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-10 20:25 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 20:25 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 20:25 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 20:25 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 20:25 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 20:25 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 20:25 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 20:25 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 20:25 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 20:25 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 20:25 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 20:25 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 20:25 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 20:25 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 20:25 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 20:25 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 20:25 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 20:25 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 20:25 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 20:25 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 20:25 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 20:25 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 20:25 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 20:25 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 20:25 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 20:25 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 20:25 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 20:25 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 20:25 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 20:25 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 20:25 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 20:25 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 20:25 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 20:25 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 20:25 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 20:25 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 20:25 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 20:25 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 20:25 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 20:25 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 20:25 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 20:25 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 20:25 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 20:25 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 20:25 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 20:25 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 20:25 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 20:25 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 20:25 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 20:25 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 20:25 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 20:25 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 20:25 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 20:25 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 20:25 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 20:25 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 20:25 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 20:25 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 20:25 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 20:25 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 20:25 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 20:25 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-10 20:25 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-10 20:25 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 20:24 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 20:24 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 20:24 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free AVCHD Converter
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\Program Files (x86)\Free AVCHD Converter
2014-07-03 20:42 - 2014-07-03 20:42 - 00007600 _____ () C:\Users\Pavel\AppData\Local\Resmon.ResmonCfg
2014-07-03 20:19 - 2014-07-05 20:44 - 00000000 ____D () C:\Users\Pavel\AppData\Local\ftblauncher
2014-07-03 20:19 - 2014-07-03 20:26 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\ftblauncher

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-07-29 22:26 - 2014-07-29 22:26 - 00029696 _____ () C:\Users\Pavel\AppData\Local\MSGBOX.EXE
2014-07-29 22:26 - 2014-07-29 22:26 - 00022833 _____ () C:\Users\Pavel\Desktop\FRST.txt
2014-07-29 22:26 - 2014-07-29 22:26 - 00015327 _____ () C:\Users\Pavel\Desktop\LM.bat
2014-07-29 22:26 - 2014-07-29 19:29 - 00000000 ____D () C:\FRST
2014-07-29 22:25 - 2014-07-29 11:03 - 00000004 _____ () C:\Windows\SysWOW64\GVTunner.ref
2014-07-29 22:25 - 2013-12-21 22:40 - 00025640 _____ (Windows (R) Server 2003 DDK provider) C:\Windows\gdrv.sys
2014-07-29 22:25 - 2013-12-21 22:27 - 00030528 _____ () C:\Windows\GVTDrv64.sys
2014-07-29 22:24 - 2014-01-01 20:20 - 00000000 ____D () C:\ProgramData\TorchCrashHandler
2014-07-29 22:24 - 2013-12-25 16:45 - 00000946 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-29 22:24 - 2013-12-21 23:19 - 00456882 _____ () C:\Windows\PFRO.log
2014-07-29 22:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-29 22:24 - 2009-07-14 06:51 - 00152941 _____ () C:\Windows\setupact.log
2014-07-29 22:23 - 2013-12-29 00:53 - 00000000 ____D () C:\Users\Pavel\AppData\Local\Conduit
2014-07-29 22:23 - 2013-12-29 00:53 - 00000000 ____D () C:\Program Files\Conduit
2014-07-29 22:23 - 2013-12-29 00:53 - 00000000 ____D () C:\Program Files (x86)\Conduit
2014-07-29 22:23 - 2013-12-21 22:13 - 01655828 _____ () C:\Windows\WindowsUpdate.log
2014-07-29 22:20 - 2013-12-24 19:41 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
2014-07-29 22:15 - 2014-07-29 21:09 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-29 21:36 - 2014-01-08 18:27 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-29 21:33 - 2014-03-03 19:28 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
2014-07-29 21:30 - 2013-12-25 16:45 - 00000950 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-29 21:12 - 2013-12-24 20:03 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Seznam.cz
2014-07-29 21:11 - 2009-07-26 20:41 - 00668866 _____ () C:\Windows\system32\perfh005.dat
2014-07-29 21:11 - 2009-07-26 20:41 - 00141526 _____ () C:\Windows\system32\perfc005.dat
2014-07-29 21:11 - 2009-07-14 07:13 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-29 21:11 - 2009-07-14 06:45 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-29 21:11 - 2009-07-14 06:45 - 00017040 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-29 21:09 - 2014-07-29 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-29 21:09 - 2014-07-29 21:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-29 21:07 - 2013-12-21 22:41 - 00000000 ____D () C:\Users\Pavel\Documents\temp
2014-07-29 19:28 - 2014-07-29 19:29 - 00112640 _____ (forum.viry.cz) C:\Users\Pavel\Desktop\FRSTLauncher.exe
2014-07-29 19:27 - 2014-07-29 19:29 - 02093568 _____ (Farbar) C:\Users\Pavel\Desktop\FRST64.exe
2014-07-29 17:49 - 2013-12-24 19:42 - 00000000 ____D () C:\ProgramData\MFAData
2014-07-29 11:37 - 2014-01-10 16:24 - 00000000 ____D () C:\Users\Pavel\AppData\Local\PMB Files
2014-07-28 18:33 - 2014-03-03 19:28 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
2014-07-28 11:04 - 2014-03-20 19:34 - 00000000 ___RD () C:\Users\Pavel\Desktop\ 
2014-07-27 11:30 - 2014-07-27 11:30 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 11:29 - 2014-01-10 16:24 - 00000000 ____D () C:\ProgramData\PMB Files
2014-07-27 11:14 - 2014-07-27 11:14 - 00000000 ____D () C:\Users\Pavel\.swt
2014-07-27 11:14 - 2013-12-21 22:10 - 00000000 ____D () C:\Users\Pavel
2014-07-27 10:59 - 2014-07-22 17:49 - 00000000 ____D () C:\Windows\System32\Tasks\NCH Software
2014-07-25 10:20 - 2013-12-24 19:41 - 00000910 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
2014-07-23 12:44 - 2013-12-24 20:18 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\AIMP3
2014-07-20 19:44 - 2014-01-20 22:43 - 00000000 ____D () C:\ProgramData\TEMP
2014-07-19 21:27 - 2014-07-19 21:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-07-16 21:23 - 2014-07-16 21:23 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-13 10:54 - 2014-01-02 20:33 - 00000000 ____D () C:\ProgramData\Origin
2014-07-12 20:35 - 2013-12-25 11:32 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Skype
2014-07-12 10:31 - 2013-12-30 22:58 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-07-12 10:31 - 2013-12-30 22:54 - 00297088 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-12 10:31 - 2013-12-30 22:54 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-07-12 10:27 - 2013-12-30 22:54 - 00280904 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2014-07-11 19:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-11 10:56 - 2009-07-14 06:45 - 03111136 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 10:55 - 2009-07-14 09:46 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 10:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 10:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-11 00:15 - 2013-12-30 17:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-11 00:13 - 2013-12-30 17:35 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-10 19:31 - 2009-07-14 07:08 - 00032634 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-09 11:36 - 2014-01-08 18:27 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 11:36 - 2014-01-08 18:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-09 11:36 - 2014-01-08 18:27 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free AVCHD Converter
2014-07-08 16:54 - 2014-07-08 16:54 - 00000000 ____D () C:\Program Files (x86)\Free AVCHD Converter
2014-07-08 16:54 - 2013-12-24 19:50 - 00000000 ____D () C:\Users\Pavel\Desktop\Programy
2014-07-05 21:56 - 2014-02-01 16:46 - 00000000 ____D () C:\ProgramData\Tunngle
2014-07-05 21:56 - 2014-01-08 16:43 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\Tunngle
2014-07-05 20:44 - 2014-07-03 20:19 - 00000000 ____D () C:\Users\Pavel\AppData\Local\ftblauncher
2014-07-03 20:47 - 2013-12-27 19:26 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\.minecraft
2014-07-03 20:42 - 2014-07-03 20:42 - 00007600 _____ () C:\Users\Pavel\AppData\Local\Resmon.ResmonCfg
2014-07-03 20:26 - 2014-07-03 20:19 - 00000000 ____D () C:\Users\Pavel\AppData\Roaming\ftblauncher
2014-07-03 10:50 - 2014-03-31 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-07-01 11:29 - 2014-03-19 19:03 - 00637952 ___SH () C:\Users\Pavel\Desktop\Thumbs.db
2014-06-29 17:21 - 2013-12-24 19:50 - 00000000 ____D () C:\Users\Pavel\Desktop\Hry

Some content of TEMP:
====================
C:\Users\Pavel\AppData\Local\Temp\ebdkbfyx.3ak.exe
C:\Users\Pavel\AppData\Local\Temp\EnableExtDll.dll
C:\Users\Pavel\AppData\Local\Temp\i4jdel0.exe
C:\Users\Pavel\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-14-g15b04d8-b2991jnks.dll
C:\Users\Pavel\AppData\Local\Temp\KMP_3.9.0.126.exe
C:\Users\Pavel\AppData\Local\Temp\LAUNCHER__6601_IL4765.EXE
C:\Users\Pavel\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Pavel\AppData\Local\Temp\SIntf16.dll
C:\Users\Pavel\AppData\Local\Temp\SIntf32.dll
C:\Users\Pavel\AppData\Local\Temp\SIntfNT.dll
C:\Users\Pavel\AppData\Local\Temp\ssins.exe
C:\Users\Pavel\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Pavel\AppData\Local\Temp\Uninstall.exe
C:\Users\Pavel\AppData\Local\Temp\utt5C56.tmp.exe
C:\Users\Pavel\AppData\Local\Temp\war3_Install.exe
C:\Users\Pavel\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Pavel\AppData\Local\Temp\_is63F0.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-28 12:15

==================== End Of Log ============================

Re: Kontrola logu / pomoc

Napsal: 29 črc 2014 21:39
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-1461227209-3297222852-4237083345-1000\...\MountPoints2: {7499d181-6cc1-11e3-8c9e-94de802fb198} - G:\autorun.exe
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.us.com/?guid={3D40BAF3-88 ... F75E83396B}
SearchScopes: HKCU - DefaultScope {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {0C054A65-B0FE-48E0-B3DE-A448111044A3} URL = http://search.us.com/serp?guid={D8F5597 ... earchTerms}
SearchScopes: HKCU - {95B7759C-8C7F-4BF1-B163-73684A933233} URL = http://mysearch.avg.com/search?cid={C06 ... 2014-02-08 18:23:10&v=17.3.1.204&pid=safeguard&sg=&sap=dsp&q={searchTerms}
SearchScopes: HKCU - {BF14B370-C886-446E-93B8-CD2B86C80740} URL = http://search.us.com/serp?guid={3D40BAF ... earchTerms}
BHO: GBHO.BHO -> {45d30484-7ded-43d9-957a-d2fd1f046511} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM - Smart Recovery 2 - {1d09c093-f71e-43c3-b948-19316cbd695e} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\18.1.7\\npsitesafety.dll No File
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Pavel\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR StartupUrls: "hxxp://mysearch.avg.com?cid={C06CA908-199B-4CC8-AC42-A1E5D82B60FA}&mid=1ed6c735a2c147d2af244597c6cb586b-b00445ead46b0ebe0415ff39fe8d78ccbc9ff932&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-08 18:23:10&v=18.1.5.512&pid=safeguard&sg=&sap=hp"
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Users\Pavel\AppData\Local\Conduit
C:\Program Files\Conduit
C:\Program Files (x86)\Conduit
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000UA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1461227209-3297222852-4237083345-1000Core.job
C:\Users\Pavel\AppData\Local\Temp
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Kontrola logu / pomoc

Napsal: 30 črc 2014 09:12
od GoStyler
Prozkoumalo to aji skryté procesy?

Re: Kontrola logu / pomoc

Napsal: 30 črc 2014 17:02
od Rudy
Prozkoumá to vše, co v PC běží, kromě většiny rootkitů, na které máme jiný soft. Vše bylo smazáno. Nastala nějaká změna?

Re: Kontrola logu / pomoc

Napsal: 30 črc 2014 17:12
od GoStyler
Podíval jsem se mu do historie a bylo tam že navštívil stránku aplikace vertity control, to dovoluje špehování mě odkudkoli z internetu... myslíte že kdybych tam měl todle, tak i to by bylo smazáno?

Re: Kontrola logu / pomoc

Napsal: 30 črc 2014 17:15
od Rudy
To vám takhle z hlavy asi nepovím. Zkuste ještě tento sken:
Stáhněte Malwarebytes Anti-Rootkit http://www.malwarebytes.org/products/mbar/

Uložte nejlépe na Plochu a rozbalte
Spusťte kliknutím na mbar
Nyní postupně klikněte na Next a Update
Po dokončení update (aktualizace) databáze klikněte opět na Next
Nechte zaškrtnute všechny tři možnosti a kliněte na Scan čímž spustíte prohledavani PC
Po dokončeni skenu (cca 5 minutek) zkontrolujte, zda-li je u všech nalezů (samozrejme pokud budou) zatržítko
Tež zkontrolujte, jestli je zatržitko u Create Restore point
Nyní klikněte na CleanUp čímž nalezenou infekci odstraníme
PC bude restartován
Složka mbar by měla obsahovat log (a zřejmě se i sám otevře) mbar-log-rok-měsíc-den (hodina-minuta-sekunda).txt, ten mi sem dejte.

Re: Kontrola logu / pomoc

Napsal: 30 črc 2014 17:25
od GoStyler
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.17207

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED
CPU speed: 3.516000 GHz
Memory total: 8551682048, free: 4213125120

Downloaded database version: v2014.07.30.05
Downloaded database version: v2014.07.17.01
Initializing...
======================
------------ Kernel report ------------
07/30/2014 18:19:25
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\DRIVERS\amd_sata.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\amd_xata.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\avgrkx64.sys
\SystemRoot\system32\DRIVERS\avgloga.sys
\SystemRoot\system32\DRIVERS\avgmfx64.sys
\SystemRoot\system32\DRIVERS\avgidsha.sys
\SystemRoot\system32\DRIVERS\dtsoftbus01.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\cdrbsdrv.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\Windows\system32\drivers\avgtpx64.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\avgtdia.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\serial.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\avgldx64.sys
\SystemRoot\system32\DRIVERS\avgidsdrivera.sys
\SystemRoot\system32\DRIVERS\avgdiska.sys
\SystemRoot\system32\DRIVERS\AppleCharger.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\atikmpag.sys
\SystemRoot\system32\DRIVERS\atikmdag.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\System32\Drivers\EtronXHCI.sys
\SystemRoot\system32\DRIVERS\usbfilter.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\serenum.sys
\SystemRoot\system32\DRIVERS\amdppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\tap0901t.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\amdiox64.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\System32\Drivers\EtronHub3.sys
\SystemRoot\System32\Drivers\USBD.SYS
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\AtihdW76.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\drivers\viahduaa.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_amd_sata.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\Drivers\adfs.SYS
\??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\Windows\gdrv.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\??\C:\Windows\GVTDrv64.sys
\??\C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk1\DR1
Upper Device Object: 0xfffffa80073aa060
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006e\
Lower Device Object: 0xfffffa8006dbe060
Lower Device Driver Name: \Driver\amd_sata\
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xfffffa80073a96e0
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006d\
Lower Device Object: 0xfffffa8006dc3060
Lower Device Driver Name: \Driver\amd_sata\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa80073a96e0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80073a9210, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80073a96e0, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006dbc040, DeviceName: Unknown, DriverName: \Driver\amd_xata\
DevicePointer: 0xfffffa8006dc3060, DeviceName: \Device\0000006d\, DriverName: \Driver\amd_sata\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 847D6BC7

Partition information:

Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 204800
Partition file system is NTFS
Partition is bootable

Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 206848 Numsec = 249860096

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 128035676160 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-2047-250049680-250069680)...
Done!
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa80073aa060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80073aab90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa80073aa060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa8006dbcac0, DeviceName: Unknown, DriverName: \Driver\amd_xata\
DevicePointer: 0xfffffa8006dbe060, DeviceName: \Device\0000006e\, DriverName: \Driver\amd_sata\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 1
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 67FB6853

Partition information:

Partition 0 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 2048 Numsec = 3907024896

Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 2000398934016 bytes
Sector size: 512 bytes

Done!
File "c:\programdata\avg2014\chjw\78963b41963aff66.dat:e054880a-6932-4a52-a4a0-853c3b2de852" is sparse (flags = 32768)
File "C:\Windows\System32\config\systemprofile\AppData\Local\Avg2014\log\avgrs.log.1" is compressed (flags = 1)
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removal finished