Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

"pro vyosek"

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Gina33
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 126
Registrován: 21 kvě 2008 10:42
Bydliště: Ostrava

"pro vyosek"

#1 Příspěvek od Gina33 »

Zdravím,nevím jestli jsem tady měla dát ten log z toho combofixu ,tak tedy začnu log z rsit :
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:24-07-2014 01
Ran by Administrator (administrator) on DIAMOND-PC on 01-08-2014 16:34:28
Running from C:\Users\Administrator\Desktop
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek) C:\Program Files\ZyXEL\NWD2205\RtlService.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-07-15] (Google Inc.)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [FixMyRegistry] => C:\Program Files\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [SpeedUpMyComputer] => C:\Program Files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe [2054776 2014-06-03] ()
ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll ()
ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll ()
ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll ()
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: 74.208.10.249 gs.apple.com
Tcpip\Parameters: [DhcpNameServer] 192.168.17.3

FireFox:
========
FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.65.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @microsoft.com/Lync,version=15.0 - C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Apps Hat - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com [2014-07-27]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]

Chrome:
=======
CHR HomePage: hxxp://www.google.cz/
CHR StartupUrls: "hxxp://www.google.cz/"
CHR Extension: (Dokumenty Google) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-24]
CHR Extension: (Disk Google) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-24]
CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-24]
CHR Extension: (Peněženka Google) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-24]
CHR Extension: (APK Downloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba [2014-06-24]
CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-24]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
U2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14658848 2013-12-10] (NVIDIA Corporation)
S4 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] () [File not signed]
R2 Realtek11nCU; C:\Program Files\ZyXEL\NWD2205\RtlService.exe [36864 2010-04-16] (Realtek) [File not signed]
S3 SwitchBoard; C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S4 Virtual Router; C:\Program Files\Virtual Router\VirtualRouterService.exe [12288 2013-02-10] (Chris Pietschmann (http://pietschsoft.com)) [File not signed]
S4 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S3 Andbus; C:\Windows\System32\DRIVERS\lgandbus.sys [14336 2010-12-07] (LG Electronics Inc.)
S3 AndDiag; C:\Windows\System32\DRIVERS\lganddiag.sys [20736 2010-12-07] (LG Electronics Inc.)
S3 AndGps; C:\Windows\System32\DRIVERS\lgandgps.sys [20096 2010-12-07] (LG Electronics Inc.)
S3 ANDModem; C:\Windows\System32\DRIVERS\lgandmodem.sys [25088 2010-12-07] (LG Electronics Inc.)
S3 androidusb; C:\Windows\System32\Drivers\lgandadb.sys [25728 2010-08-02] (Google Inc)
S3 athur; C:\Windows\System32\DRIVERS\athur.sys [1570304 2011-04-20] (Atheros Communications, Inc.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-03-08] (Disc Soft Ltd)
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [23424 2009-12-15] (Huawei Tech. Co., Ltd.)
S3 HWHandSet; C:\Windows\System32\DRIVERS\hw_quusbmdm.sys [195200 2011-10-24] (Huawei Technologies Co., Ltd.)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-05] (NVIDIA Corporation)
S3 rt61x86; C:\Windows\System32\DRIVERS\WMP54Gv41x86.sys [376160 2010-04-07] (Ralink Technology, Corp.)
S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [636008 2010-07-13] (Realtek Semiconductor Corporation )
S3 smhwser; C:\Windows\System32\DRIVERS\smhwser.sys [108032 2010-02-04] (QUALCOMM Incorporated)
S3 catchme; \??\C:\Users\ADMINI~1\AppData\Local\Temp\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [198656 2009-12-15] (Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2011-10-24] (Huawei Technologies Co., Ltd.)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 16:34 - 2014-08-01 16:35 - 00015292 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-08-01 16:34 - 2014-08-01 16:34 - 00000000 ____D () C:\FRST
2014-08-01 16:34 - 2014-07-25 08:39 - 00112640 _____ (forum.viry.cz) C:\Users\Administrator\Desktop\FRSTLauncher.exe
2014-08-01 16:34 - 2014-07-25 08:38 - 01084416 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe
2014-07-31 01:21 - 2014-07-31 01:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\CrashDumps
2014-07-31 01:20 - 2014-07-31 17:52 - 00000000 ____D () C:\Users\Administrator\Desktop\Hacktivate tool
2014-07-31 00:58 - 2014-07-31 01:20 - 00000000 ____D () C:\Users\Administrator\Desktop\Snowph Hacktivate
2014-07-31 00:56 - 2014-07-31 00:56 - 22180690 _____ () C:\Users\Administrator\Downloads\Snowph Hacktivate for iPhone 4.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 13132889 _____ () C:\Users\Administrator\Downloads\iPhone4_Hacktivate_Tool.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 13132889 _____ () C:\Users\Administrator\Desktop\iPhone4_Hacktivate_Tool.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 00002104 _____ () C:\Users\Administrator\Desktop\iPhone4_Hacktivate_Tool.lnk
2014-07-31 00:49 - 2014-07-31 00:49 - 00000000 ____D () C:\Program Files\i-ekb.ru
2014-07-31 00:49 - 2014-02-21 18:13 - 08271615 _____ (i-ekb.ru ) C:\Users\Administrator\Desktop\iPhone4_Hacktivate_Tool.exe
2014-07-31 00:20 - 2014-07-31 00:22 - 08271615 _____ (i-ekb.ru ) C:\Users\Administrator\Downloads\iPhone4_Hacktivate_Tool (1).exe
2014-07-31 00:03 - 2014-07-31 01:20 - 00000600 _____ () C:\Users\Administrator\AppData\Local\PUTTY.RND
2014-07-30 23:14 - 2014-07-30 23:14 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\Program Files\iTunes
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\Program Files\iPod
2014-07-30 19:06 - 2014-07-30 22:45 - 1204958925 _____ () C:\Users\Administrator\Desktop\iPhone3,1_7.1.2_11D257_Restore.ipsw
2014-07-30 11:50 - 2014-07-30 11:50 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-30 11:48 - 2014-07-30 11:48 - 00001218 _____ () C:\Users\Administrator\Desktop\SpeedUpMyComputer.lnk
2014-07-29 13:13 - 2014-07-31 01:38 - 00000000 ____D () C:\Users\Administrator\Desktop\iP
2014-07-29 08:27 - 2014-07-29 08:27 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-07-29 08:26 - 2014-07-30 11:50 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-07-29 08:26 - 2014-07-29 08:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-07-29 08:15 - 2014-07-29 08:15 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Administrator\Downloads\sh-remover.exe
2014-07-29 08:11 - 2014-07-30 11:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-07-27 20:00 - 2014-07-27 20:00 - 00055928 _____ () C:\ComboFix.txt
2014-07-27 19:26 - 2014-07-27 20:00 - 00000000 ____D () C:\xyz
2014-07-27 19:26 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-27 19:26 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-27 19:26 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-27 19:26 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-27 19:26 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-27 19:26 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-27 19:26 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-27 19:26 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-27 19:25 - 2014-07-27 20:00 - 00000000 ____D () C:\Qoobox
2014-07-27 19:25 - 2014-07-27 19:59 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 19:24 - 2014-07-27 19:24 - 05563277 ____R (Swearware) C:\Users\Administrator\Desktop\xyz.exe
2014-07-27 19:22 - 2014-07-27 19:24 - 05563277 _____ (Swearware) C:\Users\Administrator\Downloads\ComboFix.exe
2014-07-27 08:52 - 2014-07-27 08:52 - 00000687 _____ () C:\awh316B.tmp
2014-07-26 22:13 - 2014-07-29 13:13 - 00000000 ____D () C:\Users\Administrator\Desktop\5S MAGIC
2014-07-26 09:12 - 2014-07-26 11:23 - 00000409 _____ () C:\Users\Administrator\Desktop\Nový textový dokument (3).txt
2014-07-26 08:34 - 2014-07-26 08:34 - 00000687 _____ () C:\awhF343.tmp
2014-07-25 19:47 - 2014-07-31 01:34 - 00000286 _____ () C:\Users\Administrator\Desktop\umbrella.log
2014-07-25 19:46 - 2014-07-25 19:46 - 03458048 _____ () C:\Users\Administrator\Desktop\tinyumbrella-7.11.00.exe
2014-07-25 19:45 - 2014-07-25 19:46 - 03458048 _____ () C:\Users\Administrator\Downloads\tinyumbrella-7.11.00.exe
2014-07-25 18:14 - 2014-07-31 01:34 - 00000805 _____ () C:\Windows\system32\Drivers\etc\hosts.umbrella
2014-07-25 18:13 - 2014-07-25 18:13 - 01587847 _____ () C:\Users\Administrator\Downloads\lib-win.jar
2014-07-25 18:11 - 2014-07-25 18:12 - 02303488 _____ () C:\Users\Administrator\Downloads\tinyumbrella-5.10.15.exe
2014-07-25 18:06 - 2014-07-25 18:14 - 00003741 _____ () C:\Users\Administrator\Downloads\umbrella.log
2014-07-25 17:13 - 2014-07-25 17:13 - 00000687 _____ () C:\awh8A92.tmp
2014-07-25 14:22 - 2014-07-25 14:22 - 00000687 _____ () C:\awh1CB3.tmp
2014-07-25 13:34 - 2014-07-25 13:34 - 00000000 ____D () C:\Users\Administrator\.shsh
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Sun
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-07-25 13:33 - 2014-07-25 13:32 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-25 13:33 - 2014-07-25 13:32 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-25 13:33 - 2014-07-25 13:32 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-25 13:33 - 2014-07-25 13:32 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-07-25 13:32 - 2014-07-25 13:32 - 00000000 ____D () C:\Program Files\Java
2014-07-25 13:31 - 2014-07-27 20:00 - 00000000 ____D () C:\Users\YourProfileHere
2014-07-25 13:31 - 2012-07-04 23:33 - 00000000 ____D () C:\Users\YourProfileHere\.shsh
2014-07-25 13:30 - 2014-07-25 13:30 - 01615733 _____ () C:\Users\Administrator\Downloads\Fixbug.tinyumbrella_java.exe
2014-07-25 13:24 - 2014-07-25 13:24 - 00918952 _____ (Oracle Corporation) C:\Users\Administrator\Downloads\chromeinstall-7u65.exe
2014-07-25 13:22 - 2014-07-25 13:21 - 03347936 _____ () C:\Users\Administrator\Desktop\ssh_rd_rev04b.jar
2014-07-25 13:20 - 2014-07-25 13:21 - 03347936 _____ () C:\Users\Administrator\Downloads\ssh_rd_rev04b.jar
2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
2014-07-24 23:46 - 2014-07-24 23:46 - 20955278 _____ () C:\Users\Administrator\Desktop\IMG_20140724_225730.psd
2014-07-24 15:55 - 2014-07-24 18:47 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\SpinTires
2014-07-24 15:53 - 2014-07-24 15:53 - 00013626 _____ () C:\Users\Administrator\Downloads\x3daudio1_7.zip
2014-07-24 15:53 - 2010-02-10 09:14 - 00022360 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2014-07-24 15:50 - 2014-07-24 15:50 - 00000977 _____ () C:\Users\Administrator\Desktop\Spintires.lnk
2014-07-24 15:50 - 2014-07-24 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-07-24 15:49 - 2014-07-24 15:51 - 00000000 ____D () C:\Program Files\Spintires
2014-07-24 15:48 - 2014-07-24 15:49 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
2014-07-24 15:17 - 2014-07-31 01:33 - 00000600 _____ () C:\Users\Administrator\AppData\Roaming\winscp.rnd
2014-07-24 15:13 - 2014-07-24 15:13 - 00000999 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2014-07-24 15:13 - 2014-07-24 15:13 - 00000937 _____ () C:\Users\Public\Desktop\WinSCP.lnk
2014-07-24 15:13 - 2014-07-24 15:13 - 00000000 ____D () C:\Program Files\WinSCP
2014-07-24 14:28 - 2014-07-24 14:28 - 00000000 ____D () C:\Users\Administrator\Downloads\Spintires (2014)
2014-07-24 14:18 - 2014-07-24 14:18 - 00048985 _____ () C:\Users\Administrator\Downloads\[CzT]Spintires_2014_CZ_.torrent
2014-07-24 13:28 - 2014-07-24 13:29 - 04890560 _____ (Martin Prikryl ) C:\Users\Administrator\Downloads\winscp561setup.exe
2014-07-24 12:10 - 2014-07-24 12:10 - 00000687 _____ () C:\awh79E.tmp
2014-07-23 23:48 - 2014-07-23 23:48 - 00000687 _____ () C:\awh1BE7.tmp
2014-07-23 23:48 - 2014-07-23 23:48 - 00000000 ____D () C:\Program Files\DivX
2014-07-23 23:47 - 2014-07-23 23:47 - 00000000 ____D () C:\ProgramData\DivX
2014-07-23 23:46 - 2014-07-28 11:51 - 00000000 ____D () C:\Program Files\globalUpdate
2014-07-23 23:46 - 2014-07-23 23:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\globalUpdate
2014-07-23 23:42 - 2014-07-23 23:42 - 00352480 _____ () C:\Users\Administrator\Downloads\DivX.Web.Player.Installer__8420_il294.exe
2014-07-23 23:42 - 2014-07-23 23:42 - 00352480 _____ () C:\Users\Administrator\Downloads\DivX.Web.Player.Installer__8420_il294 (1).exe
2014-07-23 23:35 - 2014-07-23 23:35 - 00000398 _____ () C:\Users\Administrator\Desktop\Dokončit CrossFire EU stahovače.url
2014-07-22 20:57 - 2014-07-22 20:57 - 00000000 _____ () C:\Users\Administrator\Desktop\Nový textový dokument (2).txt
2014-07-22 00:13 - 2014-05-19 09:43 - 00000000 ____D () C:\Users\Administrator\Desktop\Vandal Myles Weaver Direct - Good Vandal Ep 201 (DatPiff.com)
2014-07-22 00:06 - 2014-07-22 00:11 - 49893273 _____ () C:\Users\Administrator\Downloads\Good_Vandal_Ep_2014-(DatPiff.com).zip
2014-07-21 09:19 - 2014-07-21 09:19 - 00040528 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-07-21 09:18 - 2014-07-21 09:18 - 00247296 _____ () C:\Windows\system32\hfpapi.dll
2014-07-21 09:18 - 2014-07-21 09:18 - 00179200 _____ () C:\Windows\system32\nethtsrv.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00159744 _____ () C:\Windows\system32\netupdsrv.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00108544 _____ () C:\Windows\system32\installd.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00108544 _____ () C:\Windows\system32\hfnapi.dll
2014-07-20 21:04 - 2014-07-20 21:04 - 00000000 ____D () C:\Users\Administrator\Desktop\DJ Logic - Shine Like Diamonds (2008)
2014-07-20 21:03 - 2014-07-20 21:04 - 04006822 _____ () C:\Users\Administrator\Desktop\Můj film.mp4
2014-07-20 14:06 - 2014-07-20 14:15 - 96048800 _____ () C:\Users\Administrator\Downloads\ogic-hineikeiamonds(2008).rar
2014-07-20 12:16 - 2014-07-20 12:22 - 25725668 _____ () C:\Users\Administrator\Downloads\[YTP] Prasátko Pepa #3 - Macklepeppa.mp4
2014-07-20 11:54 - 2014-07-20 11:55 - 01752699 _____ () C:\Users\Administrator\Downloads\EGO ft. Robert Burian - Žijeme len raz.mp4
2014-07-19 12:58 - 2014-07-19 12:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-07-19 12:58 - 2014-07-19 12:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-07-19 10:30 - 2014-07-19 10:30 - 00536200 _____ (Best Download Manager ) C:\Users\Administrator\Downloads\OneClickRoot.exe
2014-07-19 03:10 - 2014-07-19 03:15 - 36132870 _____ () C:\Users\Administrator\Downloads\OTA_5.2.0-5.2.1.zip
2014-07-19 03:06 - 2014-07-19 03:06 - 00025010 _____ () C:\Users\Administrator\Downloads\20561920_625d13df80c80b2647a109794117ebcf6371d2ea.cab
2014-07-19 03:06 - 2014-07-19 03:06 - 00025010 _____ () C:\Users\Administrator\Downloads\20561920_625d13df80c80b2647a109794117ebcf6371d2ea (1).cab
2014-07-19 03:00 - 2014-07-19 03:00 - 00577016 _____ () C:\Users\Administrator\Desktop\VenomKernelFlasher.rar
2014-07-19 03:00 - 2014-07-19 03:00 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Team Venom
2014-07-19 03:00 - 2014-07-19 03:00 - 00000000 ____D () C:\Users\Administrator\.android
2014-07-19 03:00 - 2014-05-20 13:28 - 01691136 _____ (Team Venom) C:\Users\Administrator\Desktop\VenomKernelFlasher.exe
2014-07-19 02:59 - 2014-07-19 03:00 - 00577016 _____ () C:\Users\Administrator\Downloads\VenomKernelFlasher.rar
2014-07-19 02:39 - 2014-07-19 02:41 - 00000000 ____D () C:\Users\Administrator\Desktop\Nová složka (2)
2014-07-19 02:26 - 2014-07-19 02:26 - 02569381 _____ () C:\Users\Administrator\Downloads\4EXTRecoveryUpdater.apk
2014-07-19 02:05 - 2014-07-18 22:54 - 792909895 _____ () C:\Users\Administrator\Desktop\ViperSC2_5.2.1.zip
2014-07-18 20:49 - 2014-07-18 22:54 - 792909895 _____ () C:\Users\Administrator\Downloads\ViperSC2_5.2.1.zip
2014-07-18 18:39 - 2014-07-18 18:39 - 00000510 _____ () C:\Users\mamka\rgmnr
2014-07-18 18:39 - 2014-07-18 18:39 - 00000000 __SHD () C:\Users\mamka\AppData\Local\EmieUserList
2014-07-18 18:39 - 2014-07-18 18:39 - 00000000 __SHD () C:\Users\mamka\AppData\Local\EmieSiteList
2014-07-18 18:38 - 2014-07-18 18:38 - 00000000 ____D () C:\Users\mamka\AppData\Roaming\Apple Computer
2014-07-18 18:38 - 2014-07-18 18:38 - 00000000 ____D () C:\Users\mamka\AppData\Local\NVIDIA Corporation
2014-07-18 18:37 - 2014-07-18 18:39 - 00000000 ____D () C:\Users\mamka
2014-07-18 18:37 - 2014-07-18 18:37 - 00001397 _____ () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-18 18:37 - 2014-07-18 18:37 - 00000020 ___SH () C:\Users\mamka\ntuser.ini
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Šablony
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Soubory cookie
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Poslední
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Okolní tiskárny
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Okolní síť
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Nabídka Start
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Dokumenty
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Obrázky
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Hudba
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Filmy
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Data aplikací
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\AppData\Local\Data aplikací
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Roaming\Adobe
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\VirtualStore
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\NVIDIA
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\Google
2014-07-18 18:37 - 2014-02-11 16:11 - 00000000 ____D () C:\Users\mamka\AppData\Local\Microsoft Help
2014-07-18 18:37 - 2009-07-14 06:42 - 00000000 ___RD () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-07-18 18:37 - 2009-07-14 06:37 - 00000000 ___RD () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-07-17 23:41 - 2014-07-17 23:41 - 03352097 _____ () C:\Users\Administrator\Desktop\b9c508ad_BSOD.jpeg
2014-07-15 23:35 - 2014-07-20 21:04 - 00013414 _____ () C:\Users\Administrator\Desktop\Můj film.wlmp
2014-07-15 23:33 - 2014-07-15 23:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-07-15 23:33 - 2014-07-15 23:33 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-07-15 23:33 - 2014-06-14 16:03 - 00218200 _____ () C:\Windows\system32\unrar.dll
2014-07-15 23:31 - 2014-07-15 23:32 - 11281415 _____ ( ) C:\Users\Administrator\Downloads\K-Lite_Codec_Pack_1060_Basic.exe
2014-07-15 23:23 - 2014-07-15 23:19 - 31519823 _____ () C:\Users\Administrator\Desktop\VIDEO0039.mp4
2014-07-14 17:48 - 2014-07-14 17:48 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-14 17:48 - 2014-07-14 17:48 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-14 17:46 - 2014-07-14 17:47 - 04770904 _____ () C:\Users\Administrator\Desktop\RogueKiller.exe
2014-07-10 23:19 - 2014-07-10 23:19 - 00000000 ____D () C:\Users\Administrator\Desktop\ogic-irtywaggzributeo
2014-07-10 23:03 - 2014-07-10 23:19 - 95477908 _____ () C:\Users\Administrator\Downloads\ogic-irtywaggzributeo.rar
2014-07-10 10:06 - 2014-07-10 10:08 - 04981042 _____ () C:\Users\Administrator\Downloads\TURBO BOOST MOD V3.03-AROMA.zip
2014-07-09 18:03 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 18:03 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 18:03 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 18:03 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 18:03 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 18:03 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 18:03 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 18:03 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 18:03 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 18:03 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 18:03 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 18:03 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 18:03 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 18:03 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 18:03 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 18:03 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 18:03 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 18:03 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 18:03 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 18:03 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 18:03 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 18:03 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 18:03 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 18:03 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 18:03 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 18:03 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 18:03 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 18:03 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 18:03 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 18:03 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 16:18 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 15:58 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 15:58 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 15:42 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 15:42 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 15:40 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 15:40 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 15:39 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 15:39 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-07 22:01 - 2014-07-23 23:35 - 00000362 _____ () C:\console.log
2014-07-07 22:01 - 2014-07-07 22:01 - 00000000 ____D () C:\Program Files\CrossFire EU
2014-07-07 01:24 - 2014-07-07 01:24 - 01405833 _____ () C:\Users\Administrator\Downloads\cz.mafra.jizdnirady.apk
2014-07-07 01:15 - 2014-07-07 01:21 - 45733125 _____ () C:\Users\Administrator\Downloads\com.mediocre.smashhit.apk
2014-07-07 01:08 - 2014-07-07 01:10 - 11010442 _____ () C:\Users\Administrator\Downloads\com.instagram.android.apk
2014-07-07 01:05 - 2014-07-07 01:07 - 12627635 _____ () C:\Users\Administrator\Downloads\com.facebook.orca.apk
2014-07-07 01:01 - 2014-07-07 01:05 - 24569511 _____ () C:\Users\Administrator\Downloads\com.facebook.katana.apk
2014-07-07 00:45 - 2014-07-07 00:46 - 15541656 _____ (HTC Corporation ) C:\Users\Administrator\Downloads\HTCDriver.exe
2014-07-06 22:58 - 2014-07-06 22:58 - 00000017 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg
2014-07-06 22:51 - 2014-07-06 23:35 - 204808696 _____ () C:\Users\Administrator\Downloads\aosb_kk_1.3.4_20140607_pyramid.zip
2014-07-03 09:07 - 2014-07-03 09:07 - 00004240 _____ () C:\Users\Administrator\Downloads\objednavka-24129278.html
2014-07-02 21:20 - 2014-07-02 21:20 - 00000418 __RSH () C:\ProgramData\ntuser.pol
2014-07-02 21:18 - 2014-07-02 21:18 - 00707354 _____ () C:\Windows\unins000.exe
2014-07-02 21:18 - 2014-07-02 21:18 - 00001541 _____ () C:\Windows\unins000.dat
2014-07-02 21:18 - 2014-07-02 21:18 - 00000000 ____D () C:\Windows\system32\GPBAK
2014-07-02 20:32 - 2014-07-14 15:50 - 00000000 ____D () C:\Users\Administrator\Downloads\Sniper.Elite.III.XBOX360-COMPLEX
2014-07-02 20:31 - 2014-07-02 20:31 - 00000821 _____ () C:\Users\Administrator\Desktop\µTorrent.lnk
2014-07-02 20:31 - 2014-07-02 20:31 - 00000801 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-02 20:29 - 2014-07-25 00:03 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-07-02 20:28 - 2014-07-02 20:28 - 00021533 _____ () C:\Users\Administrator\Downloads\[CzT]Sniper_Elite_III_XBOX_360_.torrent
2014-07-02 20:26 - 2014-07-02 20:26 - 00369736 _____ () C:\Users\Administrator\Downloads\Need_for_Speed_Pro_Street_XBOX360_MARVEL.exe
2014-07-02 13:28 - 2014-07-02 13:28 - 00168120 _____ () C:\Users\Administrator\Downloads\youtube-flash-player-update-v2.exe
2014-07-02 11:04 - 2014-07-02 11:05 - 10987202 _____ () C:\Users\Administrator\Downloads\carx_drift_racing.apk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 16:35 - 2014-08-01 16:34 - 00015292 _____ () C:\Users\Administrator\Desktop\FRST.txt
2014-08-01 16:34 - 2014-08-01 16:34 - 00000000 ____D () C:\FRST
2014-08-01 16:34 - 2014-01-21 13:47 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-01 16:34 - 2014-01-18 16:26 - 01584554 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-01 16:32 - 2014-03-23 13:58 - 00002614 _____ () C:\Windows\Tasks\Apps Hat-firefoxinstaller.job
2014-08-01 16:32 - 2014-03-23 13:58 - 00001508 _____ () C:\Windows\Tasks\Apps Hat-updater.job
2014-08-01 16:32 - 2014-03-23 13:58 - 00001464 _____ () C:\Windows\Tasks\Apps Hat-codedownloader.job
2014-08-01 16:32 - 2014-03-23 13:58 - 00001342 _____ () C:\Windows\Tasks\Apps Hat-enabler.job
2014-08-01 16:32 - 2014-01-22 20:06 - 00000250 _____ () C:\Windows\Tasks\RtlVistaStart.job
2014-08-01 16:32 - 2014-01-21 13:47 - 00000938 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-01 16:31 - 2014-04-26 22:09 - 00147790 _____ () C:\Windows\setupact.log
2014-08-01 16:31 - 2014-01-18 20:08 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-08-01 16:31 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-31 23:57 - 2014-01-18 16:17 - 01914162 _____ () C:\Windows\WindowsUpdate.log
2014-07-31 23:27 - 2009-07-14 06:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-31 23:27 - 2009-07-14 06:34 - 00014416 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-31 18:18 - 2014-02-10 10:27 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-31 17:52 - 2014-07-31 01:20 - 00000000 ____D () C:\Users\Administrator\Desktop\Hacktivate tool
2014-07-31 08:54 - 2014-04-26 22:08 - 00015222 _____ () C:\Windows\PFRO.log
2014-07-31 01:38 - 2014-07-29 13:13 - 00000000 ____D () C:\Users\Administrator\Desktop\iP
2014-07-31 01:34 - 2014-07-25 19:47 - 00000286 _____ () C:\Users\Administrator\Desktop\umbrella.log
2014-07-31 01:34 - 2014-07-25 18:14 - 00000805 _____ () C:\Windows\system32\Drivers\etc\hosts.umbrella
2014-07-31 01:34 - 2014-06-24 21:00 - 00000000 ____D () C:\Users\Administrator
2014-07-31 01:33 - 2014-07-24 15:17 - 00000600 _____ () C:\Users\Administrator\AppData\Roaming\winscp.rnd
2014-07-31 01:21 - 2014-07-31 01:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\CrashDumps
2014-07-31 01:20 - 2014-07-31 00:58 - 00000000 ____D () C:\Users\Administrator\Desktop\Snowph Hacktivate
2014-07-31 01:20 - 2014-07-31 00:03 - 00000600 _____ () C:\Users\Administrator\AppData\Local\PUTTY.RND
2014-07-31 00:56 - 2014-07-31 00:56 - 22180690 _____ () C:\Users\Administrator\Downloads\Snowph Hacktivate for iPhone 4.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 13132889 _____ () C:\Users\Administrator\Downloads\iPhone4_Hacktivate_Tool.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 13132889 _____ () C:\Users\Administrator\Desktop\iPhone4_Hacktivate_Tool.rar
2014-07-31 00:49 - 2014-07-31 00:49 - 00002104 _____ () C:\Users\Administrator\Desktop\iPhone4_Hacktivate_Tool.lnk
2014-07-31 00:49 - 2014-07-31 00:49 - 00000000 ____D () C:\Program Files\i-ekb.ru
2014-07-31 00:22 - 2014-07-31 00:20 - 08271615 _____ (i-ekb.ru ) C:\Users\Administrator\Downloads\iPhone4_Hacktivate_Tool (1).exe
2014-07-30 23:14 - 2014-07-30 23:14 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\Program Files\iTunes
2014-07-30 23:14 - 2014-07-30 23:14 - 00000000 ____D () C:\Program Files\iPod
2014-07-30 23:14 - 2014-01-18 20:48 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-07-30 22:45 - 2014-07-30 19:06 - 1204958925 _____ () C:\Users\Administrator\Desktop\iPhone3,1_7.1.2_11D257_Restore.ipsw
2014-07-30 11:50 - 2014-07-30 11:50 - 00000000 ____D () C:\Windows\system32\appmgmt
2014-07-30 11:50 - 2014-07-29 08:26 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-07-30 11:48 - 2014-07-30 11:48 - 00001218 _____ () C:\Users\Administrator\Desktop\SpeedUpMyComputer.lnk
2014-07-30 11:48 - 2014-07-29 08:11 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-07-30 11:48 - 2014-03-23 13:57 - 00000000 ____D () C:\Program Files\SmartTweak
2014-07-29 13:15 - 2014-06-24 21:06 - 00000000 ____D () C:\Users\Administrator\Desktop\UČET DIAMOND
2014-07-29 13:13 - 2014-07-26 22:13 - 00000000 ____D () C:\Users\Administrator\Desktop\5S MAGIC
2014-07-29 08:27 - 2014-07-29 08:27 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-07-29 08:26 - 2014-07-29 08:26 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-07-29 08:15 - 2014-07-29 08:15 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Administrator\Downloads\sh-remover.exe
2014-07-28 11:51 - 2014-07-23 23:46 - 00000000 ____D () C:\Program Files\globalUpdate
2014-07-27 20:06 - 2014-06-24 21:01 - 00000510 _____ () C:\Users\Administrator\rgmnr
2014-07-27 20:00 - 2014-07-27 20:00 - 00055928 _____ () C:\ComboFix.txt
2014-07-27 20:00 - 2014-07-27 19:26 - 00000000 ____D () C:\xyz
2014-07-27 20:00 - 2014-07-27 19:25 - 00000000 ____D () C:\Qoobox
2014-07-27 20:00 - 2014-07-25 13:31 - 00000000 ____D () C:\Users\YourProfileHere
2014-07-27 20:00 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-07-27 20:00 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-07-27 19:59 - 2014-07-27 19:25 - 00000000 ____D () C:\Windows\erdnt
2014-07-27 19:55 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-07-27 19:50 - 2009-07-14 04:03 - 59244544 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-27 19:50 - 2009-07-14 04:03 - 18350080 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-27 19:50 - 2009-07-14 04:03 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-27 19:50 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-27 19:50 - 2009-07-14 04:03 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-07-27 19:49 - 2014-03-23 13:58 - 00000000 ____D () C:\Program Files\Apps Hat
2014-07-27 19:24 - 2014-07-27 19:24 - 05563277 ____R (Swearware) C:\Users\Administrator\Desktop\xyz.exe
2014-07-27 19:24 - 2014-07-27 19:22 - 05563277 _____ (Swearware) C:\Users\Administrator\Downloads\ComboFix.exe
2014-07-27 12:35 - 2014-06-26 16:35 - 00001186 _____ () C:\Users\Administrator\Desktop\Nový textový dokument.txt
2014-07-27 09:31 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-27 09:06 - 2014-04-26 22:59 - 00000000 ____D () C:\The KMPlayer
2014-07-27 08:52 - 2014-07-27 08:52 - 00000687 _____ () C:\awh316B.tmp
2014-07-26 22:03 - 2014-06-24 21:36 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Apple Computer
2014-07-26 11:23 - 2014-07-26 09:12 - 00000409 _____ () C:\Users\Administrator\Desktop\Nový textový dokument (3).txt
2014-07-26 08:34 - 2014-07-26 08:34 - 00000687 _____ () C:\awhF343.tmp
2014-07-25 19:46 - 2014-07-25 19:46 - 03458048 _____ () C:\Users\Administrator\Desktop\tinyumbrella-7.11.00.exe
2014-07-25 19:46 - 2014-07-25 19:45 - 03458048 _____ () C:\Users\Administrator\Downloads\tinyumbrella-7.11.00.exe
2014-07-25 18:14 - 2014-07-25 18:06 - 00003741 _____ () C:\Users\Administrator\Downloads\umbrella.log
2014-07-25 18:13 - 2014-07-25 18:13 - 01587847 _____ () C:\Users\Administrator\Downloads\lib-win.jar
2014-07-25 18:12 - 2014-07-25 18:11 - 02303488 _____ () C:\Users\Administrator\Downloads\tinyumbrella-5.10.15.exe
2014-07-25 17:13 - 2014-07-25 17:13 - 00000687 _____ () C:\awh8A92.tmp
2014-07-25 14:22 - 2014-07-25 14:22 - 00000687 _____ () C:\awh1CB3.tmp
2014-07-25 13:34 - 2014-07-25 13:34 - 00000000 ____D () C:\Users\Administrator\.shsh
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Sun
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-25 13:33 - 2014-07-25 13:33 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-07-25 13:32 - 2014-07-25 13:33 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-25 13:32 - 2014-07-25 13:33 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-25 13:32 - 2014-07-25 13:33 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-25 13:32 - 2014-07-25 13:33 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-07-25 13:32 - 2014-07-25 13:32 - 00000000 ____D () C:\Program Files\Java
2014-07-25 13:30 - 2014-07-25 13:30 - 01615733 _____ () C:\Users\Administrator\Downloads\Fixbug.tinyumbrella_java.exe
2014-07-25 13:24 - 2014-07-25 13:24 - 00918952 _____ (Oracle Corporation) C:\Users\Administrator\Downloads\chromeinstall-7u65.exe
2014-07-25 13:21 - 2014-07-25 13:22 - 03347936 _____ () C:\Users\Administrator\Desktop\ssh_rd_rev04b.jar
2014-07-25 13:21 - 2014-07-25 13:20 - 03347936 _____ () C:\Users\Administrator\Downloads\ssh_rd_rev04b.jar
2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
2014-07-25 08:39 - 2014-08-01 16:34 - 00112640 _____ (forum.viry.cz) C:\Users\Administrator\Desktop\FRSTLauncher.exe
2014-07-25 08:38 - 2014-08-01 16:34 - 01084416 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe
2014-07-25 00:03 - 2014-07-02 20:29 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent
2014-07-24 23:46 - 2014-07-24 23:46 - 20955278 _____ () C:\Users\Administrator\Desktop\IMG_20140724_225730.psd
2014-07-24 18:47 - 2014-07-24 15:55 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\SpinTires
2014-07-24 15:53 - 2014-07-24 15:53 - 00013626 _____ () C:\Users\Administrator\Downloads\x3daudio1_7.zip
2014-07-24 15:51 - 2014-07-24 15:49 - 00000000 ____D () C:\Program Files\Spintires
2014-07-24 15:50 - 2014-07-24 15:50 - 00000977 _____ () C:\Users\Administrator\Desktop\Spintires.lnk
2014-07-24 15:50 - 2014-07-24 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-07-24 15:49 - 2014-07-24 15:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
2014-07-24 15:13 - 2014-07-24 15:13 - 00000999 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
2014-07-24 15:13 - 2014-07-24 15:13 - 00000937 _____ () C:\Users\Public\Desktop\WinSCP.lnk
2014-07-24 15:13 - 2014-07-24 15:13 - 00000000 ____D () C:\Program Files\WinSCP
2014-07-24 14:28 - 2014-07-24 14:28 - 00000000 ____D () C:\Users\Administrator\Downloads\Spintires (2014)
2014-07-24 14:18 - 2014-07-24 14:18 - 00048985 _____ () C:\Users\Administrator\Downloads\[CzT]Spintires_2014_CZ_.torrent
2014-07-24 13:29 - 2014-07-24 13:28 - 04890560 _____ (Martin Prikryl ) C:\Users\Administrator\Downloads\winscp561setup.exe
2014-07-24 12:10 - 2014-07-24 12:10 - 00000687 _____ () C:\awh79E.tmp
2014-07-23 23:48 - 2014-07-23 23:48 - 00000687 _____ () C:\awh1BE7.tmp
2014-07-23 23:48 - 2014-07-23 23:48 - 00000000 ____D () C:\Program Files\DivX
2014-07-23 23:47 - 2014-07-23 23:47 - 00000000 ____D () C:\ProgramData\DivX
2014-07-23 23:47 - 2014-01-21 13:49 - 00002187 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-23 23:46 - 2014-07-23 23:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\globalUpdate
2014-07-23 23:42 - 2014-07-23 23:42 - 00352480 _____ () C:\Users\Administrator\Downloads\DivX.Web.Player.Installer__8420_il294.exe
2014-07-23 23:42 - 2014-07-23 23:42 - 00352480 _____ () C:\Users\Administrator\Downloads\DivX.Web.Player.Installer__8420_il294 (1).exe
2014-07-23 23:35 - 2014-07-23 23:35 - 00000398 _____ () C:\Users\Administrator\Desktop\Dokončit CrossFire EU stahovače.url
2014-07-23 23:35 - 2014-07-07 22:01 - 00000362 _____ () C:\console.log
2014-07-22 20:57 - 2014-07-22 20:57 - 00000000 _____ () C:\Users\Administrator\Desktop\Nový textový dokument (2).txt
2014-07-22 00:11 - 2014-07-22 00:06 - 49893273 _____ () C:\Users\Administrator\Downloads\Good_Vandal_Ep_2014-(DatPiff.com).zip
2014-07-21 09:19 - 2014-07-21 09:19 - 00040528 _____ (nethfdrv) C:\Windows\system32\Drivers\nethfdrv.sys
2014-07-21 09:18 - 2014-07-21 09:18 - 00247296 _____ () C:\Windows\system32\hfpapi.dll
2014-07-21 09:18 - 2014-07-21 09:18 - 00179200 _____ () C:\Windows\system32\nethtsrv.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00159744 _____ () C:\Windows\system32\netupdsrv.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00108544 _____ () C:\Windows\system32\installd.exe
2014-07-21 09:18 - 2014-07-21 09:18 - 00108544 _____ () C:\Windows\system32\hfnapi.dll
2014-07-20 21:04 - 2014-07-20 21:04 - 00000000 ____D () C:\Users\Administrator\Desktop\DJ Logic - Shine Like Diamonds (2008)
2014-07-20 21:04 - 2014-07-20 21:03 - 04006822 _____ () C:\Users\Administrator\Desktop\Můj film.mp4
2014-07-20 21:04 - 2014-07-15 23:35 - 00013414 _____ () C:\Users\Administrator\Desktop\Můj film.wlmp
2014-07-20 14:15 - 2014-07-20 14:06 - 96048800 _____ () C:\Users\Administrator\Downloads\ogic-hineikeiamonds(2008).rar
2014-07-20 12:22 - 2014-07-20 12:16 - 25725668 _____ () C:\Users\Administrator\Downloads\[YTP] Prasátko Pepa #3 - Macklepeppa.mp4
2014-07-20 11:55 - 2014-07-20 11:54 - 01752699 _____ () C:\Users\Administrator\Downloads\EGO ft. Robert Burian - Žijeme len raz.mp4
2014-07-19 12:58 - 2014-07-19 12:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mozilla
2014-07-19 12:58 - 2014-07-19 12:58 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Mozilla
2014-07-19 10:30 - 2014-07-19 10:30 - 00536200 _____ (Best Download Manager ) C:\Users\Administrator\Downloads\OneClickRoot.exe
2014-07-19 03:15 - 2014-07-19 03:10 - 36132870 _____ () C:\Users\Administrator\Downloads\OTA_5.2.0-5.2.1.zip
2014-07-19 03:06 - 2014-07-19 03:06 - 00025010 _____ () C:\Users\Administrator\Downloads\20561920_625d13df80c80b2647a109794117ebcf6371d2ea.cab
2014-07-19 03:06 - 2014-07-19 03:06 - 00025010 _____ () C:\Users\Administrator\Downloads\20561920_625d13df80c80b2647a109794117ebcf6371d2ea (1).cab
2014-07-19 03:00 - 2014-07-19 03:00 - 00577016 _____ () C:\Users\Administrator\Desktop\VenomKernelFlasher.rar
2014-07-19 03:00 - 2014-07-19 03:00 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Team Venom
2014-07-19 03:00 - 2014-07-19 03:00 - 00000000 ____D () C:\Users\Administrator\.android
2014-07-19 03:00 - 2014-07-19 02:59 - 00577016 _____ () C:\Users\Administrator\Downloads\VenomKernelFlasher.rar
2014-07-19 02:41 - 2014-07-19 02:39 - 00000000 ____D () C:\Users\Administrator\Desktop\Nová složka (2)
2014-07-19 02:26 - 2014-07-19 02:26 - 02569381 _____ () C:\Users\Administrator\Downloads\4EXTRecoveryUpdater.apk
2014-07-18 22:54 - 2014-07-19 02:05 - 792909895 _____ () C:\Users\Administrator\Desktop\ViperSC2_5.2.1.zip
2014-07-18 22:54 - 2014-07-18 20:49 - 792909895 _____ () C:\Users\Administrator\Downloads\ViperSC2_5.2.1.zip
2014-07-18 18:39 - 2014-07-18 18:39 - 00000510 _____ () C:\Users\mamka\rgmnr
2014-07-18 18:39 - 2014-07-18 18:39 - 00000000 __SHD () C:\Users\mamka\AppData\Local\EmieUserList
2014-07-18 18:39 - 2014-07-18 18:39 - 00000000 __SHD () C:\Users\mamka\AppData\Local\EmieSiteList
2014-07-18 18:39 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka
2014-07-18 18:38 - 2014-07-18 18:38 - 00000000 ____D () C:\Users\mamka\AppData\Roaming\Apple Computer
2014-07-18 18:38 - 2014-07-18 18:38 - 00000000 ____D () C:\Users\mamka\AppData\Local\NVIDIA Corporation
2014-07-18 18:37 - 2014-07-18 18:37 - 00001397 _____ () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-07-18 18:37 - 2014-07-18 18:37 - 00000020 ___SH () C:\Users\mamka\ntuser.ini
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Šablony
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Soubory cookie
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Poslední
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Okolní tiskárny
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Okolní síť
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Nabídka Start
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Dokumenty
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Obrázky
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Hudba
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Documents\Filmy
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\Data aplikací
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 _SHDL () C:\Users\mamka\AppData\Local\Data aplikací
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Roaming\Adobe
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\VirtualStore
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\NVIDIA
2014-07-18 18:37 - 2014-07-18 18:37 - 00000000 ____D () C:\Users\mamka\AppData\Local\Google
2014-07-17 23:41 - 2014-07-17 23:41 - 03352097 _____ () C:\Users\Administrator\Desktop\b9c508ad_BSOD.jpeg
2014-07-15 23:33 - 2014-07-15 23:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-07-15 23:33 - 2014-07-15 23:33 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-07-15 23:32 - 2014-07-15 23:31 - 11281415 _____ ( ) C:\Users\Administrator\Downloads\K-Lite_Codec_Pack_1060_Basic.exe
2014-07-15 23:23 - 2014-06-25 17:55 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\vlc
2014-07-15 23:19 - 2014-07-15 23:23 - 31519823 _____ () C:\Users\Administrator\Desktop\VIDEO0039.mp4
2014-07-14 17:48 - 2014-07-14 17:48 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-14 17:48 - 2014-07-14 17:48 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-14 17:47 - 2014-07-14 17:46 - 04770904 _____ () C:\Users\Administrator\Desktop\RogueKiller.exe
2014-07-14 15:50 - 2014-07-02 20:32 - 00000000 ____D () C:\Users\Administrator\Downloads\Sniper.Elite.III.XBOX360-COMPLEX
2014-07-14 09:53 - 2014-02-10 20:54 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-07-14 09:53 - 2014-02-10 20:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-07-10 23:19 - 2014-07-10 23:19 - 00000000 ____D () C:\Users\Administrator\Desktop\ogic-irtywaggzributeo
2014-07-10 23:19 - 2014-07-10 23:03 - 95477908 _____ () C:\Users\Administrator\Downloads\ogic-irtywaggzributeo.rar
2014-07-10 12:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-07-10 10:08 - 2014-07-10 10:06 - 04981042 _____ () C:\Users\Administrator\Downloads\TURBO BOOST MOD V3.03-AROMA.zip
2014-07-10 08:38 - 2009-07-14 06:33 - 03851408 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 08:36 - 2014-05-06 19:10 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 08:36 - 2009-07-14 11:21 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 22:09 - 2014-01-18 20:03 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 22:02 - 2014-01-18 20:03 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 20:41 - 2014-06-26 15:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\DMCache
2014-07-09 11:43 - 2014-02-10 20:49 - 00115688 _____ () C:\Windows\system32\GDIPFONTCACHEV1.DAT
2014-07-09 10:46 - 2014-06-26 15:28 - 00000000 ____D () C:\Users\Administrator\Downloads\Compressed
2014-07-09 09:18 - 2014-02-10 10:27 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 09:18 - 2014-02-10 10:27 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-07 22:01 - 2014-07-07 22:01 - 00000000 ____D () C:\Program Files\CrossFire EU
2014-07-07 01:24 - 2014-07-07 01:24 - 01405833 _____ () C:\Users\Administrator\Downloads\cz.mafra.jizdnirady.apk
2014-07-07 01:21 - 2014-07-07 01:15 - 45733125 _____ () C:\Users\Administrator\Downloads\com.mediocre.smashhit.apk
2014-07-07 01:10 - 2014-07-07 01:08 - 11010442 _____ () C:\Users\Administrator\Downloads\com.instagram.android.apk
2014-07-07 01:07 - 2014-07-07 01:05 - 12627635 _____ () C:\Users\Administrator\Downloads\com.facebook.orca.apk
2014-07-07 01:05 - 2014-07-07 01:01 - 24569511 _____ () C:\Users\Administrator\Downloads\com.facebook.katana.apk
2014-07-07 00:46 - 2014-07-07 00:45 - 15541656 _____ (HTC Corporation ) C:\Users\Administrator\Downloads\HTCDriver.exe
2014-07-06 23:35 - 2014-07-06 22:51 - 204808696 _____ () C:\Users\Administrator\Downloads\aosb_kk_1.3.4_20140607_pyramid.zip
2014-07-06 22:58 - 2014-07-06 22:58 - 00000017 _____ () C:\Users\Administrator\AppData\Local\resmon.resmoncfg
2014-07-03 11:31 - 2014-06-24 21:00 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2014-07-03 09:07 - 2014-07-03 09:07 - 00004240 _____ () C:\Users\Administrator\Downloads\objednavka-24129278.html
2014-07-02 21:20 - 2014-07-02 21:20 - 00000418 __RSH () C:\ProgramData\ntuser.pol
2014-07-02 21:20 - 2009-07-14 04:37 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-07-02 21:18 - 2014-07-02 21:18 - 00707354 _____ () C:\Windows\unins000.exe
2014-07-02 21:18 - 2014-07-02 21:18 - 00001541 _____ () C:\Windows\unins000.dat
2014-07-02 21:18 - 2014-07-02 21:18 - 00000000 ____D () C:\Windows\system32\GPBAK
2014-07-02 20:31 - 2014-07-02 20:31 - 00000821 _____ () C:\Users\Administrator\Desktop\µTorrent.lnk
2014-07-02 20:31 - 2014-07-02 20:31 - 00000801 _____ () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2014-07-02 20:28 - 2014-07-02 20:28 - 00021533 _____ () C:\Users\Administrator\Downloads\[CzT]Sniper_Elite_III_XBOX_360_.torrent
2014-07-02 20:26 - 2014-07-02 20:26 - 00369736 _____ () C:\Users\Administrator\Downloads\Need_for_Speed_Pro_Street_XBOX360_MARVEL.exe
2014-07-02 13:28 - 2014-07-02 13:28 - 00168120 _____ () C:\Users\Administrator\Downloads\youtube-flash-player-update-v2.exe
2014-07-02 12:09 - 2014-06-26 15:28 - 00000000 ____D () C:\Users\Administrator\Downloads\Video
2014-07-02 11:05 - 2014-07-02 11:04 - 10987202 _____ () C:\Users\Administrator\Downloads\carx_drift_racing.apk

Some content of TEMP:
====================
C:\Users\Administrator\AppData\Local\temp\FixMyRegistry.exe
C:\Users\Administrator\AppData\Local\temp\SHSetup.exe
C:\Users\Administrator\AppData\Local\temp\SpeedUpMyComputer.exe
C:\Users\Administrator\AppData\Local\temp\Uninstall.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-28 09:07

==================== End Of Log ============================
Přílohy
Addition.rar
(12.04 KiB) Staženo 66 x

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: "pro vyosek"

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Kdyz uz byl CF pouzit, tak mi dejte i log z nej (C:\ComboFix.txt)
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Gina33
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 126
Registrován: 21 kvě 2008 10:42
Bydliště: Ostrava

Re: "pro vyosek"

#3 Příspěvek od Gina33 »

ComboFix 14-07-25.01 - Administrator 27.07.2014 19:28:29.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.420.1029.18.2046.1379 [GMT 2:00]
Spuštěný z: c:\users\Administrator\Desktop\xyz.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Apps Hat\ApPS hat-bho.dll
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\defaults\preferences\prefs.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\manifest.xml
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins.json
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\1_base.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\102_dealply_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\103_intext_5_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\104_jollywallet_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\123_intext_adv_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\155_ibario_pops_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\17_jQuery.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\177_crossriderDashboard.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\180_bpo_serp_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\182_openUrl.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\183_tabsWrapper.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\184_noproblemppc_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\190_pops_5_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\195_icm_convertmedia_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\207_dbWrapper.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\21_debug.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\22_resources.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\220_icm_base_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\223_imonomy_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\226_set_campaign_id_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\246_setup.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\255_bpo_serp_somo_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\263_intext_5_j_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\268_stats_ff.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\28_initializer.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\281_ibario_tier3_pops_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\47_resources_background.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\64_appApiMessage.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\7_hooks.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\72_appApiValidation.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\9_search_engine_hook.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\plugins\98_omniCommands.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\userCode\background.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\extensionData\userCode\extension.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome.manifest
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\asyncDB.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\background.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\browserAction.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\contextMenu.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\dbManager.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\dom_bg.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\fileManager.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\firefox.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\firefoxNotifications.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\firefoxOmnibox.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\message.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\pageAction.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\request.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\tabs.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\webRequest.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\api\windowsMessagingHandler.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\background.html
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\baseObject.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\browser.xul
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\addressBarChangeObserver.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\console.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\consts.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\delegate.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\extensionDataStore.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\folderIOWrapper.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\httpObserver.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\IDBWrapper.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\installer.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\logFile.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\prefs.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\progressListenerObserver.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\registry.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\reloadObserver.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\reports.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\requestObject.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\searchSettings.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\uninstallObserver.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\updateManager.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\utils.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\core\xhr.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\dialog.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\ffCoreFilesIndex.txt
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\main.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\options.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\options.xul
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\platformVersion.js
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\chrome\content\search_dialog.xul
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\install.rdf
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\locale\en-US\translations.dtd
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\button1.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\button2.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\button3.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\button4.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\button5.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\crossrider_statusbar.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\icon128.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\icon16.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\icon24.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\icon48.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\panelarrow-up.png
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\popup.html
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\skin.css
c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com\skin\update.css
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETHFDRV
-------\Service_globalUpdate
-------\Service_nethfdrv
-------\Service_NetHttpService
-------\Service_ServiceUpdater
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-06-27 do 2014-07-27 )))))))))))))))))))))))))))))))
.
.
2014-07-27 06:52 . 2014-07-27 06:52 687 ----a-w- C:\awh316B.tmp
2014-07-26 06:34 . 2014-07-26 06:34 687 ----a-w- C:\awhF343.tmp
2014-07-25 15:13 . 2014-07-25 15:13 687 ----a-w- C:\awh8A92.tmp
2014-07-25 12:22 . 2014-07-25 12:22 687 ----a-w- C:\awh1CB3.tmp
2014-07-25 11:35 . 2014-07-27 17:35 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FE5531A-EF5B-43C4-93B8-2D6B571CC885}\offreg.dll
2014-07-25 11:34 . 2014-07-25 11:34 -------- d-----w- c:\users\Administrator\.shsh
2014-07-25 11:33 . 2014-07-25 11:33 -------- d-----w- c:\programdata\Oracle
2014-07-25 11:33 . 2014-07-25 11:33 -------- d-----w- c:\program files\Common Files\Java
2014-07-25 11:33 . 2014-07-25 11:32 96680 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2014-07-25 11:32 . 2014-07-25 11:32 -------- d-----w- c:\program files\Java
2014-07-25 11:31 . 2014-07-25 11:31 -------- d-----w- c:\users\YourProfileHere
2014-07-25 07:54 . 2014-07-02 03:11 8217224 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{6FE5531A-EF5B-43C4-93B8-2D6B571CC885}\mpengine.dll
2014-07-25 07:53 . 2014-07-25 07:53 687 ----a-w- C:\awh8767.tmp
2014-07-24 13:55 . 2014-07-24 16:47 -------- d-----w- c:\users\Administrator\AppData\Roaming\SpinTires
2014-07-24 13:53 . 2010-02-10 07:14 22360 ----a-w- c:\windows\system32\X3DAudio1_7.dll
2014-07-24 13:49 . 2014-07-24 13:51 -------- d-----w- c:\program files\Spintires
2014-07-24 13:48 . 2014-07-24 13:49 -------- d-----w- c:\users\Administrator\AppData\Roaming\DAEMON Tools Lite
2014-07-24 13:13 . 2014-07-24 13:13 -------- d-----w- c:\program files\WinSCP
2014-07-24 10:10 . 2014-07-24 10:10 687 ----a-w- C:\awh79E.tmp
2014-07-23 21:48 . 2014-07-23 21:48 -------- d-----w- c:\program files\DivX
2014-07-23 21:48 . 2014-07-23 21:48 687 ----a-w- C:\awh1BE7.tmp
2014-07-23 21:47 . 2014-07-23 21:47 -------- d-----w- c:\programdata\DivX
2014-07-23 21:46 . 2014-07-23 21:46 -------- d-----w- c:\program files\globalUpdate
2014-07-23 21:46 . 2014-07-23 21:46 -------- d-----w- c:\users\Administrator\AppData\Local\globalUpdate
2014-07-23 21:46 . 2014-07-23 21:47 -------- d-----w- c:\program files\HD-V1.9
2014-07-23 21:43 . 2014-07-23 21:43 -------- d-----w- c:\program files\Common Files\Config
2014-07-23 21:43 . 2014-07-23 21:43 -------- d-----w- c:\users\Administrator\AppData\Local\21965
2014-07-21 07:19 . 2014-07-21 07:19 40528 ----a-w- c:\windows\system32\drivers\nethfdrv.sys
2014-07-21 07:18 . 2014-07-21 07:18 159744 ----a-w- c:\windows\system32\netupdsrv.exe
2014-07-21 07:18 . 2014-07-21 07:18 108544 ----a-w- c:\windows\system32\installd.exe
2014-07-21 07:18 . 2014-07-21 07:18 179200 ----a-w- c:\windows\system32\nethtsrv.exe
2014-07-21 07:18 . 2014-07-21 07:18 108544 ----a-w- c:\windows\system32\hfnapi.dll
2014-07-21 07:18 . 2014-07-21 07:18 247296 ----a-w- c:\windows\system32\hfpapi.dll
2014-07-19 10:58 . 2014-07-19 10:58 -------- d-----w- c:\users\Administrator\AppData\Local\Mozilla
2014-07-19 01:00 . 2014-07-19 01:00 -------- d-----w- c:\users\Administrator\.android
2014-07-19 01:00 . 2014-07-19 01:00 -------- d-----w- c:\users\Administrator\AppData\Roaming\Team Venom
2014-07-18 16:37 . 2014-07-18 16:39 -------- d-----w- c:\users\mamka
2014-07-15 21:33 . 2014-06-14 14:03 218200 ----a-w- c:\windows\system32\unrar.dll
2014-07-15 21:33 . 2014-07-15 21:33 -------- d-----w- c:\program files\K-Lite Codec Pack
2014-07-15 21:32 . 2014-07-15 21:32 -------- d-----w- c:\users\Administrator\AppData\Local\Programs
2014-07-14 15:48 . 2014-07-14 15:48 29160 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2014-07-14 15:48 . 2014-07-14 15:48 -------- d-----w- c:\programdata\RogueKiller
2014-07-09 14:18 . 2014-06-05 14:26 1059840 ----a-w- c:\windows\system32\lsasrv.dll
2014-07-09 13:58 . 2014-06-30 01:40 404480 ----a-w- c:\windows\system32\aepdu.dll
2014-07-09 13:58 . 2014-06-30 01:36 302592 ----a-w- c:\windows\system32\aeinv.dll
2014-07-09 13:42 . 2014-06-18 01:52 868864 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tipskins.dll
2014-07-09 13:42 . 2014-06-18 01:52 399360 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tabskb.dll
2014-07-09 13:42 . 2014-06-18 00:52 2350080 ----a-w- c:\windows\system32\win32k.sys
2014-07-09 13:42 . 2014-06-18 01:52 348672 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\tiptsf.dll
2014-07-09 13:42 . 2014-06-18 01:52 104448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipBand.dll
2014-07-09 13:42 . 2014-06-18 01:51 181760 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TabTip.exe
2014-07-09 13:42 . 2014-06-18 01:51 646144 ----a-w- c:\windows\system32\osk.exe
2014-07-09 13:42 . 2014-06-18 01:50 544768 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\TipRes.dll
2014-07-09 13:40 . 2014-06-06 09:44 509440 ----a-w- c:\windows\system32\qedit.dll
2014-07-09 13:40 . 2014-05-30 06:36 338944 ----a-w- c:\windows\system32\drivers\afd.sys
2014-07-09 13:39 . 2014-05-30 07:52 172032 ----a-w- c:\windows\system32\wdigest.dll
2014-07-09 13:39 . 2014-05-30 07:52 65536 ----a-w- c:\windows\system32\TSpkg.dll
2014-07-09 13:39 . 2014-05-30 07:52 247808 ----a-w- c:\windows\system32\schannel.dll
2014-07-09 13:39 . 2014-05-30 07:52 220160 ----a-w- c:\windows\system32\ncrypt.dll
2014-07-09 13:39 . 2014-05-30 07:52 259584 ----a-w- c:\windows\system32\msv1_0.dll
2014-07-09 13:39 . 2014-05-30 07:52 550912 ----a-w- c:\windows\system32\kerberos.dll
2014-07-09 13:39 . 2014-05-30 07:52 17408 ----a-w- c:\windows\system32\credssp.dll
2014-07-09 13:02 . 2014-06-03 09:29 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2014-07-09 13:02 . 2014-06-03 09:29 989184 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2014-07-09 13:02 . 2014-06-03 09:29 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2014-07-09 13:02 . 2014-06-03 09:29 936960 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2014-07-07 20:01 . 2014-07-07 20:01 -------- d-----w- c:\program files\CrossFire EU
2014-07-02 19:18 . 2014-07-02 19:18 -------- d-----w- c:\windows\system32\GPBAK
2014-07-02 19:18 . 2014-07-02 19:18 707354 ----a-w- c:\windows\unins000.exe
2014-07-02 18:29 . 2014-07-24 22:03 -------- d-----w- c:\users\Administrator\AppData\Roaming\uTorrent
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 07:18 . 2014-02-10 08:27 71344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 07:18 . 2014-02-10 08:27 699056 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-06-19 11:19 . 2014-04-29 14:35 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2014-05-22 12:01 . 2014-04-26 21:00 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2014-05-22 12:01 . 2014-04-26 21:00 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2014-05-20 12:43 . 2014-04-30 12:30 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2014-05-08 09:06 . 2014-06-18 16:17 2742784 ----a-w- c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-18 16:17 13824 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll
2013-10-14 02:44 . 2013-10-14 02:44 2174976 ----a-w- c:\program files\Common Files\atimpenc.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1]
@="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}"
[HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}]
2014-01-31 15:45 597360 ----a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2]
@="{853B7E05-C47D-4985-909A-D0DC5C6D7303}"
[HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}]
2014-01-31 15:45 597360 ----a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3]
@="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}"
[HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}]
2014-01-31 15:45 597360 ----a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x86.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-06-10 11:19 1730264 ----a-w- c:\progra~1\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-06-10 11:19 1730264 ----a-w- c:\progra~1\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-06-10 11:19 1730264 ----a-w- c:\progra~1\MICROS~4\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949"="c:\program files\Google\Chrome\Application\chrome.exe" [2014-07-15 860488]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"="c:\program files\NVIDIA Corporation\Update Core\NvBackend.exe" [2013-12-10 2279712]
"ShadowPlay"="c:\windows\system32\nvspcap.dll" [2013-12-10 982232]
"MSStp"="c:\windows\system32\msstp.vbe" [2014-01-19 1419]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2014-05-26 152392]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-07-11 256896]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-01-19 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TP-LINK Wireless Configuration Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk
backup=c:\windows\pss\TP-LINK Wireless Configuration Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Virtual Router Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Virtual Router Manager.lnk
backup=c:\windows\pss\Virtual Router Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Wireless N USB Utility.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Wireless N USB Utility.lnk
backup=c:\windows\pss\Wireless N USB Utility.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Creative Cloud]
2014-02-02 10:43 2239376 ----a-w- c:\program files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2013-12-10 17:18 472984 ----a-w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
2012-02-22 12:33 1073312 ----a-w- c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2014-02-12 19:57 43848 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
c:\users\Diamond\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2013-10-28 08:29 3675352 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2014-05-26 17:12 152392 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncjpsjjfSrv]
2014-01-19 18:57 1342 --s-a-w- c:\windows\inf\mncjpsjjf.vbe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
2013-10-02 19:28 1090912 ----a-w- c:\program files\Nokia\Nokia Suite\NokiaSuite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2014-01-17 15:24 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
2013-05-16 13:25 1062472 ----a-w- c:\program files\Seznam.cz\distribution\szninstall.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer]
2013-07-22 12:34 2054776 ----a-w- c:\program files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
2010-02-19 12:37 517096 ----a-w- c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
.
2;2 NvNetworkService;NVIDIA Network Service;c:\program files\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-10-23 172192]
R3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\DRIVERS\lgandbus.sys [2010-12-07 14336]
R3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\DRIVERS\lganddiag.sys [2010-12-07 20736]
R3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\DRIVERS\lgandgps.sys [2010-12-07 20096]
R3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\DRIVERS\lgandmodem.sys [2010-12-07 25088]
R3 androidusb;ADB Interface Driver;c:\windows\system32\Drivers\lgandadb.sys [2010-08-02 25728]
R3 athur;Atheros AR9271 Wireless Network Adapter Service;c:\windows\system32\DRIVERS\athur.sys [2011-04-20 1570304]
R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);c:\program files\globalUpdate\Update\GoogleUpdate.exe [2014-07-23 68608]
R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088]
R3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\DRIVERS\htcnprot.sys [2012-12-07 23040]
R3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader;c:\windows\system32\DRIVERS\ewdcsc.sys [2009-12-15 23424]
R3 HWHandSet;HWUSBSERSP;c:\windows\system32\DRIVERS\hw_quusbmdm.sys [2011-10-24 195200]
R3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\DRIVERS\ewusbdev.sys [2009-12-15 101120]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 rt61x86;Linksys Wireless-G PCI Adapter Driver;c:\windows\system32\DRIVERS\WMP54Gv41x86.sys [2010-04-07 376160]
R3 RTL8192cu;Wireless N USB Utility;c:\windows\system32\DRIVERS\RTL8192cu.sys [2010-07-13 636008]
R3 smhwser;USB Device for Legacy Serial Communication (Normal);c:\windows\system32\DRIVERS\smhwser.sys [2010-02-04 108032]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2014-01-18 1343400]
R4 Virtual Router;VirtualRouterService;c:\program files\Virtual Router\VirtualRouterService.exe [2013-02-10 12288]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-03-08 243128]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-04-11 1390720]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-04-11 1764992]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2013-12-10 14658848]
S2 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [2012-12-07 167424]
S2 Realtek11nCU;Realtek11nCU;c:\program files\ZyXEL\NWD2205\RtlService.exe [2010-04-16 36864]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-12-19 411936]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-04-02 4972864]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [2013-12-05 34080]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-07-19 00:36 1104200 ----a-w- c:\program files\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-07-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-10 07:18]
.
2014-07-27 c:\windows\Tasks\AmiUpdXp.job
- c:\users\Administrator\AppData\Local\21965\a31949.exe [2014-07-23 21:42]
.
2014-07-27 c:\windows\Tasks\Apps Hat-codedownloader.job
- c:\program files\Apps Hat\Apps Hat-codedownloader.exe [2014-03-23 11:58]
.
2014-07-27 c:\windows\Tasks\Apps Hat-enabler.job
- c:\program files\Apps Hat\Apps Hat-enabler.exe [2014-03-23 11:58]
.
2014-07-27 c:\windows\Tasks\Apps Hat-firefoxinstaller.job
- c:\program files\Apps Hat\Apps Hat-firefoxinstaller.exe [2014-03-23 11:58]
.
2014-07-27 c:\windows\Tasks\Apps Hat-updater.job
- c:\program files\Apps Hat\Apps Hat-updater.exe [2014-03-23 11:58]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-1.job
- c:\program files\HD-V1.9\HD-V1.9-codedownloader.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-10.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-10.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-11.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-11.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-2.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-2.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-3.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-3.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-4.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-4.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-5.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-5.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-5_user.job
- c:\program files\HD-V1.9\bfcab333-6924-4351-92f0-d0acd12943a4-5.exe [2014-07-23 21:47]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-6.job
- c:\program files\HD-V1.9\HD-V1.9-novainstaller.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\bfcab333-6924-4351-92f0-d0acd12943a4-7.job
- c:\program files\HD-V1.9\HD-V1.9-nova.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job
- c:\program files\globalUpdate\Update\GoogleUpdate.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\globalUpdateUpdateTaskMachineUA.job
- c:\program files\globalUpdate\Update\GoogleUpdate.exe [2014-07-23 21:46]
.
2014-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-01-21 11:47]
.
2014-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2014-01-21 11:47]
.
2014-07-27 c:\windows\Tasks\RtlVistaStart.job
- c:\program files\ZyXEL\NWD2205\NWD2205.exe [2014-01-22 16:32]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do Microsoft Excelu - c:\progra~1\MICROS~4\Office15\EXCEL.EXE/3000
IE: Od&eslat do OneNotu - c:\progra~1\MICROS~4\Office15\ONBttnIE.dll/105
TCP: Interfaces\{5E205938-3508-4F44-9B98-F4EF3EEE6803}: NameServer = 192.168.17.3
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{F241C880-6982-4CE5-8CF7-7085BA96DA5A} - (no file)
ShellIconOverlayIdentifiers-{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} - (no file)
ShellIconOverlayIdentifiers-{BBACC218-34EA-4666-9D7A-C78F2274A524} - (no file)
MSConfigStartUp-cz.seznam.software - c:\users\Diamond\AppData\Roaming\Seznam.cz\szninstall.exe
MSConfigStartUp-FixMyRegistry - c:\program files\SmartTweak\FixMyRegistry\FixMyRegistry.exe
MSConfigStartUp-FLV Player - c:\users\Diamond\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe
AddRemove-FilesFrog Update Checker - c:\users\Diamond\AppData\Local\FilesFrog Update Checker\uninstall.exe
AddRemove-Flvto Youtube Downloader - c:\users\Diamond\AppData\Local\Flvto Youtube Downloader\UninstallFlvtoYoutubeDownloader.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,81,a6,a5,03,47,0a,33,44,a7,63,d3,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,81,a6,a5,03,47,0a,33,44,a7,63,d3,\
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aif"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aifc"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.aiff"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.cda"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cdda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.cdda"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipa"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipg"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ipsw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ipsw"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itdb\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itdb"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ite\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.ite"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itl"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itlp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itlp"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itls"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itms"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.itpc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.itpc"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jar\UserChoice]
@Denied: (2) (Administrator)
"Progid"="jarfile"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u8\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m3u8"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4a"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4b"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4p"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4r\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4r"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.m4v"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.mp2"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.mp3"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcast\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pcast"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.pls"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wav"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wave\UserChoice]
@Denied: (2) (Administrator)
"Progid"="iTunes.wave"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML"
.
[HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\System32\WUDFHost.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
c:\windows\system32\conhost.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Celkový čas: 2014-07-27 20:00:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-07-27 18:00
.
Před spuštěním: Volných bajtů: 120 980 365 312
Po spuštění: Volných bajtů: 120 743 059 456
.
- - End Of File - - 2A82F7E346B60F0BD509CD23293FF192
A36C5E4F47E84449FF07ED3517B43A31

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: "pro vyosek"

#4 Příspěvek od vyosek »

:arrow: Stahnete Junkware Removal Tool http://thisisudax.org/downloads/JRT.exe
  • Ulozte nejlepe na plochu
  • Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
  • Probehne vytvoreni zalohy a nasledne prohledavani
  • Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte
:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Gina33
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 126
Registrován: 21 kvě 2008 10:42
Bydliště: Ostrava

Re: "pro vyosek"

#5 Příspěvek od Gina33 »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Administrator on p  01.08.2014 at 18:02:42,75
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\speedupmycomputer



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smarttweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\installedbrowserextensions
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\speedupmycomputer
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048559.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048559.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0048559.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422852259}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550455855559}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655055548}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466856659}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666056648}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048559.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048559.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0048559.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550455855559}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655055548}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466856659}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666056648}



~~~ Files

Successfully deleted: [File] "C:\Windows\Tasks\Apps Hat-firefoxinstaller.job"
Successfully deleted: [File] "C:\Windows\Tasks\Apps Hat-updater.job"
Successfully deleted: [File] "C:\Windows\Tasks\Apps Hat-codedownloader.job"
Successfully deleted: [File] "C:\Windows\Tasks\Apps Hat-enabler.job"
Successfully deleted: [File] "C:\Windows\System32\Tasks\Apps Hat-enabler"
Successfully deleted: [File] "C:\Windows\System32\Tasks\Apps Hat-firefoxinstaller"
Successfully deleted: [File] "C:\Windows\System32\Tasks\Apps Hat-updater"
Successfully deleted: [File] "C:\Windows\System32\Tasks\Apps Hat-codedownloader"



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Administrator\appdata\locallow\apps hat"
Successfully deleted: [Folder] "C:\Program Files\apps hat"
Successfully deleted: [Folder] "C:\Program Files\smarttweak"
Successfully deleted: [Folder] "C:\Users\Administrator\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"



~~~ FireFox

Successfully deleted the following from C:\Users\Administrator\AppData\Roaming\mozilla\firefox\profiles\tdf2akh3.default\prefs.js

user_pref("extensions.a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559.48559.internaldb.Resources_meta.value", "%7B%2219x19.png%22%3A%7B%22id%22%3A485
user_pref("extensions.a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559.48559.internaldb.Resources_resource_485550.value", "%22data%3Aimage/png%3Bbase6
user_pref("extensions.a39ed7c16185d4f88b976666d4928ba01fe4550c17a4f4a62ad1c45e0afdf81a4com48559.48559.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "1475013d4faa3ba4c0cd374a60f1d33d");



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on p  01.08.2014 at 18:05:32,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Gina33
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 126
Registrován: 21 kvě 2008 10:42
Bydliště: Ostrava

Re: "pro vyosek"

#6 Příspěvek od Gina33 »

# AdwCleaner v3.302 - Report created 01/08/2014 at 18:07:51
# Updated 30/07/2014 by Xplode
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)
# Username : Administrator - DIAMOND-PC
# Running from : C:\Users\Administrator\Desktop\adwcleaner_3.302.exe
# Option : Clean

***** [ Services ] *****

[#] Service Deleted : globalUpdatem

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\RegClean
Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Users\Administrator\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com
File Deleted : C:\Windows\system32\drivers\nethfdrv.sys
File Deleted : C:\Windows\system32\hfpapi.dll
File Deleted : C:\Windows\system32\installd.exe
File Deleted : C:\Windows\system32\nethtsrv.exe
File Deleted : C:\Windows\system32\netupdsrv.exe
File Deleted : C:\Users\ADMINI~1\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
File Deleted : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FixMyRegistry]
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKLM\Software\GlobalUpdate
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17207


-\\ Mozilla Firefox v26.0 (cs)

[ File : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\prefs.js ]


-\\ Google Chrome v36.0.1985.125

[ File : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\preferences ]


[ File : C:\Users\mamka\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [3215 octets] - [01/08/2014 18:06:44]
AdwCleaner[S0].txt - [3198 octets] - [01/08/2014 18:07:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3258 octets] ##########

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: "pro vyosek"

#7 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-20] (Microsoft Corporation)
    HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-07-15] (Google Inc.)
    HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
    HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [FixMyRegistry] => C:\Program Files\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as
    HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [SpeedUpMyComputer] => C:\Program Files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe [2054776 2014-06-03] ()
    
    FF Extension: Apps Hat - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com [2014-07-27]
    FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
    
    CHR Extension: (APK Downloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba [2014-06-24]
    CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
    
    R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
    S4 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]
    C:\Program Files\Skype\Toolbars
    
    S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
    S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]
    
    2014-08-01 16:34 - 2014-07-25 08:39 - 00112640 _____ (forum.viry.cz) C:\Users\Administrator\Desktop\FRSTLauncher.exe
    2014-07-29 08:27 - 2014-07-29 08:27 - 00000000 ____D () C:\Program Files\Enigma Software Group
    2014-07-29 08:15 - 2014-07-29 08:15 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Administrator\Downloads\sh-remover.exe
    2014-07-29 08:11 - 2014-07-30 11:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
    2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
    2014-07-25 17:13 - 2014-07-25 17:13 - 00000687 _____ () C:\awh8A92.tmp
    2014-07-25 14:22 - 2014-07-25 14:22 - 00000687 _____ () C:\awh1CB3.tmp
    2014-07-27 08:52 - 2014-07-27 08:52 - 00000687 _____ () C:\awh316B.tmp
    2014-07-26 08:34 - 2014-07-26 08:34 - 00000687 _____ () C:\awhF343.tmp
    2014-07-24 12:10 - 2014-07-24 12:10 - 00000687 _____ () C:\awh79E.tmp
    2014-07-23 23:48 - 2014-07-23 23:48 - 00000687 _____ () C:\awh1BE7.tmp
    2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
    2014-07-23 23:46 - 2014-07-28 11:51 - 00000000 ____D () C:\Program Files\globalUpdate
    2014-07-23 23:46 - 2014-07-23 23:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\globalUpdate
    2014-07-14 17:48 - 2014-07-14 17:48 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
    2014-07-14 17:48 - 2014-07-14 17:48 - 00000000 ____D () C:\ProgramData\RogueKiller
    2014-07-14 17:46 - 2014-07-14 17:47 - 04770904 _____ () C:\Users\Administrator\Desktop\RogueKiller.exe
    C:\Users\Administrator\AppData\Local\temp\FixMyRegistry.exe
    C:\Users\Administrator\AppData\Local\temp\SHSetup.exe
    C:\Users\Administrator\AppData\Local\temp\SpeedUpMyComputer.exe
    C:\Users\Administrator\AppData\Local\temp\Uninstall.exe
    
    Task: {4AC33E40-1523-474B-9DA1-36D4BB99ECC5} - System32\Tasks\Apps Hat-enabler => C:\Program Files\Apps Hat\Apps Hat-enabler.exe [2014-03-23] (Nero) <==== ATTENTION
    Task: {82557641-3824-4632-BA52-60FC16717FF7} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-02-10] ()
    Task: {82A13737-DD96-4EF2-AB69-39148C66F7BE} - System32\Tasks\Apps Hat-firefoxinstaller => C:\Program Files\Apps Hat\Apps Hat-firefoxinstaller.exe [2014-03-23] (Nero) <==== ATTENTION
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\Apps Hat-codedownloader.job => C:\Program Files\Apps Hat\Apps Hat-codedownloader.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Apps Hat-enabler.job => C:\Program Files\Apps Hat\Apps Hat-enabler.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Apps Hat-firefoxinstaller.job => C:\Program Files\Apps Hat\Apps Hat-firefoxinstaller.exe <==== ATTENTION
    Task: C:\Windows\Tasks\Apps Hat-updater.job => C:\Program Files\Apps Hat\Apps Hat-updater.exe <==== ATTENTION
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\RtlVistaStart.job => C:\Program Files\ZyXEL\NWD2205\NWD2205.exe
    
    Hosts:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Gina33
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 126
Registrován: 21 kvě 2008 10:42
Bydliště: Ostrava

Re: "pro vyosek"

#8 Příspěvek od Gina33 »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:31-07-2014 02
Ran by Administrator at 2014-08-01 21:48:46 Run:1
Running from C:\Users\Administrator\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-20] (Microsoft Corporation)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949] => C:\Program Files\Google\Chrome\Application\chrome.exe [860488 2014-07-15] (Google Inc.)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [FixMyRegistry] => C:\Program Files\SmartTweak\FixMyRegistry\FixMyRegistry.exe /ot /as
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\...\Run: [SpeedUpMyComputer] => C:\Program Files\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe [2054776 2014-06-03] ()

FF Extension: Apps Hat - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com [2014-07-27]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]

CHR Extension: (APK Downloader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba [2014-06-24]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]

R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
S4 globalUpdatem; C:\Program Files\globalUpdate\Update\GoogleUpdate.exe /medsvc [X]
C:\Program Files\Skype\Toolbars

S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

2014-08-01 16:34 - 2014-07-25 08:39 - 00112640 _____ (forum.viry.cz) C:\Users\Administrator\Desktop\FRSTLauncher.exe
2014-07-29 08:27 - 2014-07-29 08:27 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-07-29 08:15 - 2014-07-29 08:15 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Administrator\Downloads\sh-remover.exe
2014-07-29 08:11 - 2014-07-30 11:48 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software
2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
2014-07-25 17:13 - 2014-07-25 17:13 - 00000687 _____ () C:\awh8A92.tmp
2014-07-25 14:22 - 2014-07-25 14:22 - 00000687 _____ () C:\awh1CB3.tmp
2014-07-27 08:52 - 2014-07-27 08:52 - 00000687 _____ () C:\awh316B.tmp
2014-07-26 08:34 - 2014-07-26 08:34 - 00000687 _____ () C:\awhF343.tmp
2014-07-24 12:10 - 2014-07-24 12:10 - 00000687 _____ () C:\awh79E.tmp
2014-07-23 23:48 - 2014-07-23 23:48 - 00000687 _____ () C:\awh1BE7.tmp
2014-07-25 09:53 - 2014-07-25 09:53 - 00000687 _____ () C:\awh8767.tmp
2014-07-23 23:46 - 2014-07-28 11:51 - 00000000 ____D () C:\Program Files\globalUpdate
2014-07-23 23:46 - 2014-07-23 23:46 - 00000000 ____D () C:\Users\Administrator\AppData\Local\globalUpdate
2014-07-14 17:48 - 2014-07-14 17:48 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-07-14 17:48 - 2014-07-14 17:48 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-07-14 17:46 - 2014-07-14 17:47 - 04770904 _____ () C:\Users\Administrator\Desktop\RogueKiller.exe
C:\Users\Administrator\AppData\Local\temp\FixMyRegistry.exe
C:\Users\Administrator\AppData\Local\temp\SHSetup.exe
C:\Users\Administrator\AppData\Local\temp\SpeedUpMyComputer.exe
C:\Users\Administrator\AppData\Local\temp\Uninstall.exe

Task: {4AC33E40-1523-474B-9DA1-36D4BB99ECC5} - System32\Tasks\Apps Hat-enabler => C:\Program Files\Apps Hat\Apps Hat-enabler.exe [2014-03-23] (Nero) <==== ATTENTION
Task: {82557641-3824-4632-BA52-60FC16717FF7} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-02-10] ()
Task: {82A13737-DD96-4EF2-AB69-39148C66F7BE} - System32\Tasks\Apps Hat-firefoxinstaller => C:\Program Files\Apps Hat\Apps Hat-firefoxinstaller.exe [2014-03-23] (Nero) <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Apps Hat-codedownloader.job => C:\Program Files\Apps Hat\Apps Hat-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\Apps Hat-enabler.job => C:\Program Files\Apps Hat\Apps Hat-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\Apps Hat-firefoxinstaller.job => C:\Program Files\Apps Hat\Apps Hat-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\Apps Hat-updater.job => C:\Program Files\Apps Hat\Apps Hat-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\RtlVistaStart.job => C:\Program Files\ZyXEL\NWD2205\NWD2205.exe

Hosts:
Reboot:
End
*****************

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-01-20] (Microsoft Corporation) => Value not found.
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949 => value deleted successfully.
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Run\\FixMyRegistry => Value not found.
HKU\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Run\\SpeedUpMyComputer => Value not found.
C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\tdf2akh3.default\Extensions\39ed7c16-185d-4f88-b976-666d4928ba01@fe4550c1-7a4f-4a62-ad1c-45e0afdf81a4.com => not found.
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully.
C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba => Moved successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl" => Key deleted successfully.
C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx => Moved successfully.
c2cautoupdatesvc => Service stopped successfully.
c2cautoupdatesvc => Service deleted successfully.
c2cpnrsvc => Service stopped successfully.
c2cpnrsvc => Service deleted successfully.
globalUpdatem => Service not found.
C:\Program Files\Skype\Toolbars => Moved successfully.
Synth3dVsc => Service deleted successfully.
tsusbhub => Service deleted successfully.
VGPU => Service deleted successfully.
"C:\Users\Administrator\Desktop\FRSTLauncher.exe" => File/Directory not found.
C:\Program Files\Enigma Software Group => Moved successfully.
C:\Users\Administrator\Downloads\sh-remover.exe => Moved successfully.
"C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartTweak Software" => File/Directory not found.
C:\awh8767.tmp => Moved successfully.
C:\awh8A92.tmp => Moved successfully.
C:\awh1CB3.tmp => Moved successfully.
C:\awh316B.tmp => Moved successfully.
C:\awhF343.tmp => Moved successfully.
C:\awh79E.tmp => Moved successfully.
C:\awh1BE7.tmp => Moved successfully.
"C:\awh8767.tmp" => File/Directory not found.
"C:\Program Files\globalUpdate" => File/Directory not found.
"C:\Users\Administrator\AppData\Local\globalUpdate" => File/Directory not found.
C:\Windows\system32\Drivers\TrueSight.sys => Moved successfully.
C:\ProgramData\RogueKiller => Moved successfully.
C:\Users\Administrator\Desktop\RogueKiller.exe => Moved successfully.
C:\Users\Administrator\AppData\Local\temp\FixMyRegistry.exe => Moved successfully.
C:\Users\Administrator\AppData\Local\temp\SHSetup.exe => Moved successfully.
C:\Users\Administrator\AppData\Local\temp\SpeedUpMyComputer.exe => Moved successfully.
"C:\Users\Administrator\AppData\Local\temp\Uninstall.exe" => File/Directory not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4AC33E40-1523-474B-9DA1-36D4BB99ECC5}" => Key not found.
C:\Windows\System32\Tasks\Apps Hat-enabler not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-enabler" => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{82557641-3824-4632-BA52-60FC16717FF7}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82557641-3824-4632-BA52-60FC16717FF7}" => Key deleted successfully.
C:\Windows\System32\Tasks\AutoKMS => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82A13737-DD96-4EF2-AB69-39148C66F7BE}" => Key not found.
C:\Windows\System32\Tasks\Apps Hat-firefoxinstaller not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apps Hat-firefoxinstaller" => Key not found.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\Apps Hat-codedownloader.job not found.
C:\Windows\Tasks\Apps Hat-enabler.job not found.
C:\Windows\Tasks\Apps Hat-firefoxinstaller.job not found.
C:\Windows\Tasks\Apps Hat-updater.job not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\RtlVistaStart.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.


The system needed a reboot.

==== End of Fixlog ====

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: "pro vyosek"

#9 Příspěvek od vyosek »

:arrow: Pokud nemate, tak presunte Combofix na plochu
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    KillAll::
    
    Folder::
    c:\users\Administrator\AppData\Local\21965
    c:\program files\Apps Hat
    c:\program files\HD-V1.9
    c:\users\Administrator\AppData\Local\globalUpdate
    
    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS6ServiceManager]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cz.seznam.software.szndesktop]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mncjpsjjfSrv]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NokiaSuite.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyComputer]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwitchBoard]
    
    Collect::
    c:\windows\inf\mncjpsjjf.vbe
    
    RegLock::
    [HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Internet Explorer\User Preferences]
    [HKEY_USERS\S-1-5-21-2555081224-2359601201-1085997456-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    
    ClearJavaCache::
    
    Reboot::
  • Ulozte vytvoreny TXT jako CFScript.txt
  • Pretahnete vytvoreny CFScript.txt nad Combofix a pustte (viz obrazek nize)
    Obrázek
  • Po aplikaci skriptu (a pripadnem restartu) na Vas vypadne log, jeho obsah sem vlozte
:arrow: Pokud vyskoci hlaska "Pokus pouzit neplatnou operaci na klic registru, ktery je oznacen pro odstraneni", tak jen restartujte PC - registr se da do kupy - jedna se o vnitrni chybu, kterou zpusobuje CF a autor ji zatim neumi bohuzel opravit

:arrow: Muze se stat, ze po aplikaci skriptu nenabehnou windows, v tomto pripade restartuje PC a mackejte F8 a zvolte Posledni znamou konfiguraci
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět