
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Zavirovaný ntb
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zavirovaný ntb
Dobrý den,
opět se obracím s notebookem své přítelkyně. Nevím jak se jí to vždy povede ale má počítač plnej nesmyslu. Problémy co jsem vypozoroval z jednoho sezeni jsou : Internet plný vyskakujících reklam, google chrome hází neustále chybu ''profil nelze správně otevřít'', po zavření nelze spustit bez ukonceni rozlišení v task masteru,.. v počítači vidím nějaký optimizer pro a buh vi co jeste....
Tímto Vás chci požádat o kontrolu a radu jak s těmito problémy naložit
Děkuji
Rsit:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Nikola at 2014-11-12 08:30:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 156 GB (36%) free of 432 GB
Total RAM: 3067 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:30:26, on 12.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nikola.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.creativetoolbars.com/?src ... martbar&g=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: 3cbeccd0f561013193a909dd7c8eb7090062182 - {11111111-1111-1111-1111-110611211182} - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CoolSaleCoupon - {a4feea9e-7905-4969-8886-69b16d909c6b} - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKCU\..\Run: [NextLive] C:\windows\SysWOW64\rundll32.exe "C:\Users\Nikola\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\_OTM\MovedFiles\09112013_163548\C_Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: lxdi_device - - C:\windows\system32\lxdicoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Messenger Plus! Service (MsgPlusService) - Unknown owner - C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater12.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: wgclbhvqtgnwlt - Company (R) - c:\windows\SysWOW64\HUAYNF~1.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14419 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
c:\windows\SysWOW64\HUAYNF~1.EXE
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
atieclxx
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\windows\system32\lxdicoms.exe -service
"C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2136
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll",ENT
"C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll",ENT
taskeng.exe {7C6537F6-A6F0-46ED-AF32-4BD58F17F601}
"C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"C:\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.exe" /rawdata=K/bKQIGL8XQOVW4/nwE1xvIYd52+oK+8ARAZzil2QMgJFnsXUV4DOJiHvVb+9irzoYuby/y8b5SYafzLYuQy8jInq7Y8yQc7XXx+RHJ1kiFQno9xWX9iPWHyqcHwRuimdoYeGpoTyL0ZYIxkFU2MXWkPUawzGi1InXauHE7TdkoYEUcgXrLhpVYwgfGvbr0dmyTw4FCZ2NOFDyp/fL9BpsVzEzyqvm+nIWVopupTE8/ryyDA6e9b+VGSeRCu9yGGfmdZesbNfabCWuREF2mxsBmtKnjtxXQ72QC2czNuxiJbsC7NylCNOQWR1hb83kzH2p+o/9jXbT1gDPtEvFcOG6NNAXW/NIGJYh8Y9g15mbk0FSWEI6pu1HCxZls/DVv9UPkHXS703LCD4za3LKrV8md7qHScfbDCjPm2EXYqkfjGrniU11GtM/Xyr2/myy4mffxDxOe1DJm1yzhPdwQ8cwa1lRf5Axye20Br5C82OGkfc+VenZoMboAzb6ovUL7eT3Of3Zdgb3+FfWaI/g+P2jVcSBhVVAK/MXfHuYvr3/2y/4d62Orvjfdpu4l7HDLRtUyAK40AU/iW6Qc23vV614UApjSBmE8o5dLRrpPVXDaETufvl8k+IIgL1WuMcX3AJ6+wCgkr2QXxqoRZLbqxChmL0gnUMGRQIoRcVLLUE1C/ADKMNE4vh7IluEXdHbhsSj44mUo2p765vRiRtLUhBV2qvTK2NoHG4K7afwNk8//zXGzcHX4F+t4gt3qOECdW90xnQdZb3vulhJsTajqnjqEiPm0JRVMJgI9AgX4u3/gBT7ngOCLE9CuupQZN7/nIwwW4u3SktaRkE7qFnioJVGd17o5Uefm4+22ZW9xyx4xKZCS/FMEmrPXeCbNMuaDrVB7CcgzDViJpHn6n3TImKHYhhNED8eToKDydHNxR2tKrZw9ZpXgJAmXxURjkgbsWX8R1MuB2YyFHl9ckyfN3LQT/Y5Uj/J5KVatNZ+tFbQYHtdK6/zy8SQDJbDsGxI+znv7p2L0NkJg84q3yp43MeFxde5WLs2PH3qT0H+Um6fd7zokTgBNzXeLbQcP6Ke+kTgGNBbKMNgHSoWHj/OFPjPN5X0Rbj3As10EwCfdNKeLjJKKHYx54yAWkGGHGJrZOW4VCkYdl56UYZhBT/PIwNALDP7sxjkw6+Jj5yw3oFabF5ydn7b+4sb0NxC3Fw/wMHRG+vrGlvw7iqMxQx6qYoPf8isJFzso+CgKVlBwvq+J6PPjciQjfGTDfHK6qfOTYPjSmiJASti47iGx14aDTXgskbjljSXSLianwrv0TbQDb7wDUKuDnXH1d1Z+6/fvxURJByqzSFBa5VTeR/8W5uIE+StjJxND/iGEweYjVjcJeUzTvHIW3rRo6e+DKgLlEAJ3QNY8mM3q0YBDwtMFrXs9gl0uJMlkT8HzGnsLMXnIh7naDEsjtvjaXc9isytPT1seDitd77IkOMhHkwSkfEl0PAJQhVN58Isb0tNEWnVzR5wMBwyrbUn18dXu0trNQqRyATcy9Z53294IObgvnHRYbNZDAYu7OK1wKnTZ5hRT+Yqg0v2OUn4nmtivoT3J/+w5IESiPriSvld/hDTSCR2CKnUdomMLa33MzXfI84LT9wQF8Sz8r7mrbgGqisIplpI07n0q8ryuGQiUc/aXR5tthzSc+1+jWKCzVA1KaQ7U3OdD+Dl+aX6MEUwXlp3ga3NF69CcvURS/VGefZYBbP8nWPOGX1+N7NW18pjIi4hb6RbaSxjWcYyOvq3g9c7tFsmkd1KeZKQP8DTQCV9HajdRmv5DVfhQ68nOg4g0Ica+m+d/kIE+BXSbGoJ27mo4iLYC+R1O1q8RNTHDcsge8Oz4SrHJ+NYT0B9tsQKLeUmXUKT/hI40gyFj66HPxE7Kj7R5gF47C4ud+jQSTEjHjcmvLvRaV+XVynOb8VY5P0z9GJuE/O3ae3nF7qW1sshxqY4Mh6KAA553lqo6Z8WKEduTlYLtFmcqGEnHDa6w/tmDoXc9rNyVeCwLR7wpJwFg3anTkpYewmOkeNL6DLESsFVXowDVKQB9JnFr/6H2Bque4lpFQ+pJUeM7tZHhE2emHcdR2qxCIjiQ6vIeelwaci3BE2QocHauRG2/JvekC7qk30DzdGM6J9RwZXTVlmwAShxvMiYR00PKZvdYoSWsxxWJOi4d8BkzJSp26G8iaCHW4O2SaJGkuGUiUrkSYkYcpKG+RniU5qv7zlx7qKbkcudi43GWAnCGH2azo4tuh5Z4qipDoP3z1rDiHOke/qNoyx2Rm0jZNKyWh66IEIxPHKZWm4vfDuiyRiPO1D3UKh531R4dit0xcYwnTBfifbBeniTo/IDHblkzOaRWoUTYh+UdNwH9/m1I/ktq7WiAhnqcx5IdZsw4BhxNGM0aNwa04umPgwz8nv9fhPUvMMRirkr6HAKRc0rJoXwANYt4e3wUPeIwdm8Tj7nbeIW9+yxuxhgWgId4dmwLDoUVWUVoBbBkC09TpbVx3QaQgQ+IenNaGE2dSUxfgWrc/4N4hHPWh
"C:\windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5660.0.1069758652\427154321" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.0.0 --ignored=" --type=renderer " /prefetch:822062411
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 dev:pp5 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/None/MaterialDesignNTP/Default/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Enabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_21/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --channel="5660.7.1068084734\260347130" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 dev:pp5 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/None/MaterialDesignNTP/Default/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Enabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_21/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --channel="5660.15.921526880\1224045444" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5660.16.1058930900\1045492586" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Nikola\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-1.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5_user.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7.job
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AmiUpdXp.job
C:\windows\tasks\globalUpdateUpdateTaskMachineCore.job
C:\windows\tasks\globalUpdateUpdateTaskMachineUA.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0}.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://search.creativetoolbars.com/?src ... martbar&g="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin]
"Description"=McAfee Mss Plugin
"Path"=C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\
50db678457b16@50db678457b4f.com
chang.gibbons98@aol.com
info@thebflix.com
speedanalysis03@SpeedAnalysis.com
staged
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\
Google.xml
smartbar.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}]
Shopp_Upe_1.8 - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho64.dll [2014-11-10 859040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}]
CoolSaleCoupon - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.x64.dll [2014-11-10 904704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF103732-4528-4322-AA8B-F7849AB7776B}]
7Go Games - C:\Program Files (x86)\7Go Games\ScriptHost64.dll [2013-07-30 382272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}]
Shopp_Upe_1.8 - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll [2014-11-10 632224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}]
CoolSaleCoupon - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll [2014-11-10 768000]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-17 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-27 10775584]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2010-04-27 2040352]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-07 1894696]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [2010-04-12 4462496]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2010-03-18 7056800]
"lxdimon.exe"=C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [2007-05-07 435120]
"lxdiamon"=C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [2007-03-05 20480]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"=C:\windows\SysWOW64\rundll32.exe [2009-07-14 44544]
"GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-10-22 854344]
"Optimizer Pro"=C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [2014-11-04 148048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529]
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-10-22 854344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
C:\Program Files (x86)\PDF24\pdf24.exe [2012-02-02 220744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2013-10-23 377368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe [2009-08-11 1080608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-02 98304]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"YouCam Mirror Tray icon"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2010-03-02 171104]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"FaxCenterServer"=C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [2007-05-07 312240]
"Freecorder FLV Service"=C:\Program Files (x86)\Freecorder\FLVSrvc.exe /run []
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"IJNetworkScannerSelectorEX"=C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2013-02-19 453736]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-10-07 843480]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\_OTM\MovedFiles\09112013_163548\C_Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-11-12 08:30:16 ----D---- C:\rsit
2014-11-10 17:54:04 ----D---- C:\ProgramData\CheapCoupon
2014-11-10 17:52:33 ----D---- C:\ProgramData\CoolSaleCoupon
2014-11-10 17:52:19 ----D---- C:\ProgramData\44ddf37e9357dff0
2014-11-10 15:13:16 ----D---- C:\Program Files (x86)\BlueStacks
2014-11-10 15:09:30 ----D---- C:\Users\Nikola\AppData\Roaming\Optimizer Pro
2014-11-10 15:06:36 ----D---- C:\Program Files (x86)\b2c1a4d4-496e-421e-bdd6-d933c230e3fb
2014-11-10 15:05:39 ----D---- C:\Program Files (x86)\globalUpdate
2014-11-10 15:05:30 ----D---- C:\Program Files (x86)\Shopp_Upe_1.8
2014-11-10 15:03:33 ----D---- C:\Program Files (x86)\Optimizer Pro
2014-11-04 21:58:36 ----D---- C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58:22 ----A---- C:\windows\SYSWOW64\CNHMCA.dll
2014-11-04 21:58:22 ----A---- C:\windows\SYSWOW64\CNC_BVL.dll
2014-11-04 21:56:39 ----D---- C:\windows\system32\STRING
2014-11-04 21:56:39 ----A---- C:\windows\SYSWOW64\CNMNPPM.DLL
2014-11-04 21:56:39 ----A---- C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56:39 ----A---- C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:54:35 ----A---- C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51:00 ----HD---- C:\ProgramData\CanonIJETV
2014-10-26 07:10:47 ----D---- C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09:27 ----HD---- C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52:22 ----D---- C:\ProgramData\CanonIJWSpt
2014-10-26 06:39:00 ----D---- C:\ProgramData\CanonIJPLM
2014-10-26 06:36:49 ----D---- C:\Program Files (x86)\Canon
2014-10-16 16:25:55 ----A---- C:\windows\system32\win32k.sys
2014-10-16 16:25:49 ----A---- C:\windows\SYSWOW64\mscorier.dll
2014-10-16 16:25:49 ----A---- C:\windows\system32\mscorier.dll
2014-10-16 16:25:48 ----A---- C:\windows\SYSWOW64\dfshim.dll
2014-10-16 16:25:48 ----A---- C:\windows\system32\dfshim.dll
2014-10-16 16:25:47 ----A---- C:\windows\SYSWOW64\mscories.dll
2014-10-16 16:25:47 ----A---- C:\windows\system32\mscories.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-10-16 16:25:28 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-10-16 16:25:28 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-10-16 16:25:28 ----A---- C:\windows\system32\iernonce.dll
2014-10-16 16:25:28 ----A---- C:\windows\system32\ie4uinit.exe
2014-10-16 16:25:27 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25:27 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-10-16 16:25:27 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25:27 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25:26 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-10-16 16:25:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-10-16 16:25:24 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-10-16 16:25:23 ----A---- C:\windows\system32\iedkcs32.dll
2014-10-16 16:25:22 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-10-16 16:25:22 ----A---- C:\windows\system32\urlmon.dll
2014-10-16 16:25:22 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25:21 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-10-16 16:25:21 ----A---- C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25:20 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-10-16 16:25:20 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-10-16 16:25:20 ----A---- C:\windows\system32\msfeeds.dll
2014-10-16 16:25:20 ----A---- C:\windows\system32\dxtmsft.dll
2014-10-16 16:25:19 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-10-16 16:25:18 ----A---- C:\windows\system32\iesetup.dll
2014-10-16 16:25:16 ----A---- C:\windows\system32\iertutil.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-10-16 16:25:14 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-10-16 16:25:14 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-10-16 16:25:13 ----A---- C:\windows\system32\jsproxy.dll
2014-10-16 16:25:11 ----A---- C:\windows\system32\ieui.dll
2014-10-16 16:25:11 ----A---- C:\windows\system32\dxtrans.dll
2014-10-16 16:25:10 ----A---- C:\windows\system32\ieframe.dll
2014-10-16 16:25:09 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25:09 ----A---- C:\windows\system32\mshtmled.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\jscript9diag.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\jscript9.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\ieUnatt.exe
2014-10-16 16:25:07 ----A---- C:\windows\system32\vbscript.dll
2014-10-16 16:25:07 ----A---- C:\windows\system32\ieapfltr.dll
2014-10-16 16:25:05 ----A---- C:\windows\system32\wininet.dll
2014-10-16 16:25:04 ----A---- C:\windows\system32\msrating.dll
2014-10-16 16:25:04 ----A---- C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25:02 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25:01 ----A---- C:\windows\system32\mshtml.dll
2014-10-16 16:23:35 ----A---- C:\windows\SYSWOW64\rastls.dll
2014-10-16 16:23:35 ----A---- C:\windows\system32\rastls.dll
2014-10-16 16:23:21 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-10-16 16:23:20 ----A---- C:\windows\system32\mstscax.dll
2014-10-16 16:23:18 ----A---- C:\windows\system32\mstsc.exe
2014-10-16 16:23:17 ----A---- C:\windows\system32\termsrv.dll
2014-10-16 16:23:16 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-10-16 16:23:14 ----A---- C:\windows\SYSWOW64\winsta.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\winsta.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\schannel.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\drivers\rdpwd.sys
2014-10-16 16:23:13 ----A---- C:\windows\SYSWOW64\schannel.dll
2014-10-16 16:23:13 ----A---- C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23:12 ----A---- C:\windows\SYSWOW64\aaclient.dll
2014-10-16 16:23:12 ----A---- C:\windows\system32\winlogon.exe
2014-10-16 16:23:11 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2014-10-16 16:23:11 ----A---- C:\windows\system32\wdigest.dll
2014-10-16 16:23:11 ----A---- C:\windows\system32\msv1_0.dll
2014-10-16 16:23:10 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2014-10-16 16:23:10 ----A---- C:\windows\system32\ncrypt.dll
2014-10-16 16:23:09 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2014-10-16 16:23:09 ----A---- C:\windows\system32\TSpkg.dll
2014-10-16 16:23:08 ----A---- C:\windows\SYSWOW64\wdigest.dll
2014-10-16 16:23:08 ----A---- C:\windows\SYSWOW64\credssp.dll
2014-10-16 16:23:08 ----A---- C:\windows\system32\credssp.dll
2014-10-16 16:23:07 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2014-10-16 16:22:24 ----A---- C:\windows\system32\packager.dll
2014-10-16 16:22:23 ----A---- C:\windows\SYSWOW64\packager.dll
======List of files/folders modified in the last 1 month======
2014-11-12 08:30:26 ----D---- C:\windows\Prefetch
2014-11-12 08:30:21 ----D---- C:\Program Files\trend micro
2014-11-12 08:29:28 ----D---- C:\windows\system32\catroot2
2014-11-12 08:29:28 ----D---- C:\windows\system32\catroot
2014-11-12 08:29:16 ----D---- C:\windows\Temp
2014-11-12 08:29:09 ----D---- C:\windows\winsxs
2014-11-12 08:20:26 ----D---- C:\windows\system32\config
2014-11-11 21:35:04 ----D---- C:\windows\SysWOW64
2014-11-11 21:35:01 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-11-11 00:00:06 ----SHD---- C:\System Volume Information
2014-11-10 17:54:04 ----HD---- C:\ProgramData
2014-11-10 17:51:38 ----D---- C:\windows\Microsoft.NET
2014-11-10 15:18:36 ----SHD---- C:\windows\Installer
2014-11-10 15:18:35 ----RSD---- C:\windows\assembly
2014-11-10 15:16:41 ----D---- C:\Program Files (x86)
2014-11-10 15:14:24 ----D---- C:\ProgramData\BlueStacks
2014-11-10 15:09:40 ----D---- C:\windows\system32\Tasks
2014-11-10 15:09:36 ----D---- C:\windows\Tasks
2014-11-10 15:07:06 ----D---- C:\Program Files (x86)\7Go Games
2014-11-10 15:04:29 ----D---- C:\ProgramData\BlueStacksSetup
2014-11-09 19:53:15 ----D---- C:\windows\System32
2014-11-09 19:53:15 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-11-09 19:53:14 ----D---- C:\windows\inf
2014-11-08 21:33:56 ----D---- C:\Users\Nikola\AppData\Roaming\newnext.me
2014-11-08 21:15:40 ----D---- C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58:26 ----RSD---- C:\windows\Media
2014-11-04 21:58:21 ----D---- C:\windows\twain_32
2014-11-04 21:55:16 ----HD---- C:\Program Files\CanonBJ
2014-11-04 21:55:15 ----D---- C:\windows\system32\DriverStore
2014-11-04 21:41:44 ----D---- C:\ProgramData\Lx_cats
2014-10-31 06:25:49 ----D---- C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40:05 ----D---- C:\filmy
2014-10-30 12:25:26 ----N---- C:\windows\system32\MpSigStub.exe
2014-10-28 20:30:40 ----HD---- C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30:37 ----HD---- C:\ProgramData\CanonBJ
2014-10-28 20:30:36 ----RD---- C:\Program Files
2014-10-28 20:30:33 ----D---- C:\windows\registration
2014-10-28 19:37:54 ----D---- C:\windows\system32\NDF
2014-10-28 19:31:53 ----D---- C:\windows\system32\wfp
2014-10-28 19:31:49 ----D---- C:\windows\system32\wbem
2014-10-28 19:31:49 ----D---- C:\Windows
2014-10-18 00:31:59 ----D---- C:\windows\rescache
2014-10-17 18:20:17 ----D---- C:\windows\system32\drivers
2014-10-17 18:17:04 ----D---- C:\windows\SYSWOW64\en-US
2014-10-17 18:17:04 ----D---- C:\Program Files\Internet Explorer
2014-10-17 18:17:03 ----D---- C:\windows\system32\en-US
2014-10-17 18:17:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-17 18:17:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-10-17 18:17:01 ----D---- C:\windows\system32\cs-CZ
2014-10-17 18:16:06 ----D---- C:\ProgramData\Microsoft Help
2014-10-17 17:39:59 ----D---- C:\windows\system32\MRT
2014-10-17 16:24:46 ----A---- C:\windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2010-01-15 39008]
R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2012-08-30 31080]
R1 SCDEmu;SCDEmu; C:\windows\system32\drivers\SCDEmu.sys [2013-10-23 129944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-10-07 122072]
R2 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2009-11-06 1550848]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
R3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
R3 Cam5607;Lenovo EasyCamera ; C:\windows\System32\Drivers\BisonC07.sys [2010-04-20 1270896]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2010-04-27 2357024]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-07 302128]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11280]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-16 79376]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\windows\system32\DRIVERS\netaapl64.sys [2013-07-25 23040]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\windows\syswow64\drivers\pcdrndisuio.sys [2009-12-17 19456]
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0;PCDSRVC{A14E314B-3E985FDA-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\f:\pcdoctor\pcdsrvc_x64.pkms []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-03-12 242720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBAAPL64;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 151656]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 70e6ca8c;Optimizer Pro Crash Monitor; C:\windows\syswow64\rundll32.exe [2009-07-14 44544]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-03-03 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-10-07 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [2014-10-07 782040]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2009-08-11 864032]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-05-14 140936]
R2 lxdi_device;lxdi_device; C:\windows\system32\lxdicoms.exe [2007-04-26 876976]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [2013-03-10 186760]
R2 wgclbhvqtgnwlt;wgclbhvqtgnwlt; c:\windows\SysWOW64\HUAYNF~1.EXE [2012-04-15 102400]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-08-01 641352]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-10-07 409304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S2 MsgPlusService;Messenger Plus! Service; C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe []
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 vToolbarUpdater12.2.0;vToolbarUpdater12.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 IGRS;IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-04-07 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-10-03 150600]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-05-08 1255736]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
opět se obracím s notebookem své přítelkyně. Nevím jak se jí to vždy povede ale má počítač plnej nesmyslu. Problémy co jsem vypozoroval z jednoho sezeni jsou : Internet plný vyskakujících reklam, google chrome hází neustále chybu ''profil nelze správně otevřít'', po zavření nelze spustit bez ukonceni rozlišení v task masteru,.. v počítači vidím nějaký optimizer pro a buh vi co jeste....
Tímto Vás chci požádat o kontrolu a radu jak s těmito problémy naložit
Děkuji
Rsit:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Nikola at 2014-11-12 08:30:16
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 156 GB (36%) free of 432 GB
Total RAM: 3067 MB (46% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:30:26, on 12.11.2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17344)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Nikola.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.creativetoolbars.com/?src ... martbar&g=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: 3cbeccd0f561013193a909dd7c8eb7090062182 - {11111111-1111-1111-1111-110611211182} - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: CoolSaleCoupon - {a4feea9e-7905-4969-8886-69b16d909c6b} - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0"
O4 - HKLM\..\Run: [YouCam Mirror Tray icon] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKCU\..\Run: [NextLive] C:\windows\SysWOW64\rundll32.exe "C:\Users\Nikola\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\_OTM\MovedFiles\09112013_163548\C_Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-Service.exe
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - BlueStack Systems, Inc. - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\windows\system32\fxssvc.exe (file missing)
O23 - Service: globalUpdate Update Service (globalUpdate) (globalUpdate) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: globalUpdate Update Service (globalUpdatem) (globalUpdatem) - globalUpdate - C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: IGRS - Lenovo Group Limited - C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: Lenovo ReadyComm AppSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\AppSvc.exe
O23 - Service: Lenovo ReadyComm ConnSvc - Lenovo Group Limited - C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe
O23 - Service: lxdi_device - - C:\windows\system32\lxdicoms.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - Unknown owner - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\windows\System32\msdtc.exe (file missing)
O23 - Service: Messenger Plus! Service (MsgPlusService) - Unknown owner - C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\windows\system32\vssvc.exe (file missing)
O23 - Service: vToolbarUpdater12.2.0 - Unknown owner - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\windows\system32\wbengine.exe (file missing)
O23 - Service: wgclbhvqtgnwlt - Company (R) - c:\windows\SysWOW64\HUAYNF~1.EXE
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 14419 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\lsm.exe
winlogon.exe
C:\windows\system32\svchost.exe -k DcomLaunch
c:\windows\SysWOW64\HUAYNF~1.EXE
C:\windows\system32\svchost.exe -k RPCSS
"c:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
atieclxx
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe"
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\windows\system32\lxdicoms.exe -service
"C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe"
C:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 2136
"c:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\windows\system32\svchost.exe -k bthsvcs
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\windows\system32\Dwm.exe"
C:\windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE3
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe"
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM"
"C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe" 0
"C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll",ENT
"C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro\OptProCrash.dll",ENT
taskeng.exe {7C6537F6-A6F0-46ED-AF32-4BD58F17F601}
"C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe"
"C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe"
"C:\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.exe" /rawdata=K/bKQIGL8XQOVW4/nwE1xvIYd52+oK+8ARAZzil2QMgJFnsXUV4DOJiHvVb+9irzoYuby/y8b5SYafzLYuQy8jInq7Y8yQc7XXx+RHJ1kiFQno9xWX9iPWHyqcHwRuimdoYeGpoTyL0ZYIxkFU2MXWkPUawzGi1InXauHE7TdkoYEUcgXrLhpVYwgfGvbr0dmyTw4FCZ2NOFDyp/fL9BpsVzEzyqvm+nIWVopupTE8/ryyDA6e9b+VGSeRCu9yGGfmdZesbNfabCWuREF2mxsBmtKnjtxXQ72QC2czNuxiJbsC7NylCNOQWR1hb83kzH2p+o/9jXbT1gDPtEvFcOG6NNAXW/NIGJYh8Y9g15mbk0FSWEI6pu1HCxZls/DVv9UPkHXS703LCD4za3LKrV8md7qHScfbDCjPm2EXYqkfjGrniU11GtM/Xyr2/myy4mffxDxOe1DJm1yzhPdwQ8cwa1lRf5Axye20Br5C82OGkfc+VenZoMboAzb6ovUL7eT3Of3Zdgb3+FfWaI/g+P2jVcSBhVVAK/MXfHuYvr3/2y/4d62Orvjfdpu4l7HDLRtUyAK40AU/iW6Qc23vV614UApjSBmE8o5dLRrpPVXDaETufvl8k+IIgL1WuMcX3AJ6+wCgkr2QXxqoRZLbqxChmL0gnUMGRQIoRcVLLUE1C/ADKMNE4vh7IluEXdHbhsSj44mUo2p765vRiRtLUhBV2qvTK2NoHG4K7afwNk8//zXGzcHX4F+t4gt3qOECdW90xnQdZb3vulhJsTajqnjqEiPm0JRVMJgI9AgX4u3/gBT7ngOCLE9CuupQZN7/nIwwW4u3SktaRkE7qFnioJVGd17o5Uefm4+22ZW9xyx4xKZCS/FMEmrPXeCbNMuaDrVB7CcgzDViJpHn6n3TImKHYhhNED8eToKDydHNxR2tKrZw9ZpXgJAmXxURjkgbsWX8R1MuB2YyFHl9ckyfN3LQT/Y5Uj/J5KVatNZ+tFbQYHtdK6/zy8SQDJbDsGxI+znv7p2L0NkJg84q3yp43MeFxde5WLs2PH3qT0H+Um6fd7zokTgBNzXeLbQcP6Ke+kTgGNBbKMNgHSoWHj/OFPjPN5X0Rbj3As10EwCfdNKeLjJKKHYx54yAWkGGHGJrZOW4VCkYdl56UYZhBT/PIwNALDP7sxjkw6+Jj5yw3oFabF5ydn7b+4sb0NxC3Fw/wMHRG+vrGlvw7iqMxQx6qYoPf8isJFzso+CgKVlBwvq+J6PPjciQjfGTDfHK6qfOTYPjSmiJASti47iGx14aDTXgskbjljSXSLianwrv0TbQDb7wDUKuDnXH1d1Z+6/fvxURJByqzSFBa5VTeR/8W5uIE+StjJxND/iGEweYjVjcJeUzTvHIW3rRo6e+DKgLlEAJ3QNY8mM3q0YBDwtMFrXs9gl0uJMlkT8HzGnsLMXnIh7naDEsjtvjaXc9isytPT1seDitd77IkOMhHkwSkfEl0PAJQhVN58Isb0tNEWnVzR5wMBwyrbUn18dXu0trNQqRyATcy9Z53294IObgvnHRYbNZDAYu7OK1wKnTZ5hRT+Yqg0v2OUn4nmtivoT3J/+w5IESiPriSvld/hDTSCR2CKnUdomMLa33MzXfI84LT9wQF8Sz8r7mrbgGqisIplpI07n0q8ryuGQiUc/aXR5tthzSc+1+jWKCzVA1KaQ7U3OdD+Dl+aX6MEUwXlp3ga3NF69CcvURS/VGefZYBbP8nWPOGX1+N7NW18pjIi4hb6RbaSxjWcYyOvq3g9c7tFsmkd1KeZKQP8DTQCV9HajdRmv5DVfhQ68nOg4g0Ica+m+d/kIE+BXSbGoJ27mo4iLYC+R1O1q8RNTHDcsge8Oz4SrHJ+NYT0B9tsQKLeUmXUKT/hI40gyFj66HPxE7Kj7R5gF47C4ud+jQSTEjHjcmvLvRaV+XVynOb8VY5P0z9GJuE/O3ae3nF7qW1sshxqY4Mh6KAA553lqo6Z8WKEduTlYLtFmcqGEnHDa6w/tmDoXc9rNyVeCwLR7wpJwFg3anTkpYewmOkeNL6DLESsFVXowDVKQB9JnFr/6H2Bque4lpFQ+pJUeM7tZHhE2emHcdR2qxCIjiQ6vIeelwaci3BE2QocHauRG2/JvekC7qk30DzdGM6J9RwZXTVlmwAShxvMiYR00PKZvdYoSWsxxWJOi4d8BkzJSp26G8iaCHW4O2SaJGkuGUiUrkSYkYcpKG+RniU5qv7zlx7qKbkcudi43GWAnCGH2azo4tuh5Z4qipDoP3z1rDiHOke/qNoyx2Rm0jZNKyWh66IEIxPHKZWm4vfDuiyRiPO1D3UKh531R4dit0xcYwnTBfifbBeniTo/IDHblkzOaRWoUTYh+UdNwH9/m1I/ktq7WiAhnqcx5IdZsw4BhxNGM0aNwa04umPgwz8nv9fhPUvMMRirkr6HAKRc0rJoXwANYt4e3wUPeIwdm8Tj7nbeIW9+yxuxhgWgId4dmwLDoUVWUVoBbBkC09TpbVx3QaQgQ+IenNaGE2dSUxfgWrc/4N4hHPWh
"C:\windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5660.0.1069758652\427154321" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,16 --gpu-vendor-id=0x1002 --gpu-device-id=0x68e0 --gpu-driver-vendor="ATI Technologies Inc." --gpu-driver-version=8.712.0.0 --ignored=" --type=renderer " /prefetch:822062411
C:\windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 dev:pp5 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/None/MaterialDesignNTP/Default/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Enabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_21/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --channel="5660.7.1068084734\260347130" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --lang=cs --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/control/EmbeddedSearch/Group1 dev:pp5 prefetch_results:1 reuse_instant_search_base_page:1/EnableSessionCrashedBubbleUI/Enabled/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/None/MaterialDesignNTP/Default/NewProfileManagement/NewAvatarMenu/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Enabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/cd=3:LocalPredictor=Disabled/RapporRollout/Enabled/RememberCertificateErrorDecisions/Default/SafeBrowsingIncidentReportingService/Enabled/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-1-Percent/group_21/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_08/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --channel="5660.15.921526880\1224045444" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="5660.16.1058930900\1045492586" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Users\Nikola\Downloads\RSITx64.exe"
C:\windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-1.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5_user.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.job
C:\windows\tasks\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7.job
C:\windows\tasks\Adobe Flash Player Updater.job
C:\windows\tasks\AmiUpdXp.job
C:\windows\tasks\globalUpdateUpdateTaskMachineCore.job
C:\windows\tasks\globalUpdateUpdateTaskMachineUA.job
C:\windows\tasks\GoogleUpdateTaskMachineCore.job
C:\windows\tasks\GoogleUpdateTaskMachineUA.job
C:\windows\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0}.job
=========Mozilla firefox=========
ProfilePath - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "http://search.creativetoolbars.com/?src ... martbar&g="
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=]
"Description"=iTunes Detector Plug-in
"Path"=
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0]
"Description"=
"Path"=C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Picasa3\npPicasa3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin]
"Description"=McAfee Mss Plugin
"Path"=C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4]
"Description"=globalUpdate Update
"Path"=C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
C:\Program Files (x86)\Mozilla Firefox\components\
nsIQTScriptablePlugin.xpt
C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
npqtplugin.dll
npqtplugin2.dll
npqtplugin3.dll
npqtplugin4.dll
npqtplugin5.dll
npqtplugin6.dll
npqtplugin7.dll
QuickTimePlugin.class
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\
50db678457b16@50db678457b4f.com
chang.gibbons98@aol.com
info@thebflix.com
speedanalysis03@SpeedAnalysis.com
staged
{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
{ea614400-e918-4741-9a97-7a972ff7c30b}
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\
Google.xml
smartbar.xml
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}]
Shopp_Upe_1.8 - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho64.dll [2014-11-10 859040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}]
CoolSaleCoupon - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.x64.dll [2014-11-10 904704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF103732-4528-4322-AA8B-F7849AB7776B}]
7Go Games - C:\Program Files (x86)\7Go Games\ScriptHost64.dll [2013-07-30 382272]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}]
Shopp_Upe_1.8 - C:\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll [2014-11-10 632224]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-17 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}]
CoolSaleCoupon - C:\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll [2014-11-10 768000]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-17 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2010-04-27 10775584]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2010-04-27 2040352]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-01-07 1894696]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [2010-04-12 4462496]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2010-03-18 7056800]
"lxdimon.exe"=C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [2007-05-07 435120]
"lxdiamon"=C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [2007-03-05 20480]
"MSC"=c:\Program Files\Microsoft Security Client\msseces.exe [2014-08-22 1331288]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"NextLive"=C:\windows\SysWOW64\rundll32.exe [2009-07-14 44544]
"GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-10-22 854344]
"Optimizer Pro"=C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [2014-11-04 148048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529]
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2014-10-22 854344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint]
C:\Program Files (x86)\PDF24\pdf24.exe [2012-02-02 220744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE [2013-10-23 377368]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-02-10 20922016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager]
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe [2009-08-11 1080608]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2010-03-02 98304]
"UCam_Menu"=C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [2009-05-19 222504]
"YouCam Mirror Tray icon"=C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [2010-03-02 171104]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2008-12-03 218408]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
"FaxCenterServer"=C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [2007-05-07 312240]
"Freecorder FLV Service"=C:\Program Files (x86)\Freecorder\FLVSrvc.exe /run []
"WinampAgent"=C:\Program Files (x86)\Winamp\winampa.exe []
"ROC_roc_ssl_v12"=C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe / /PROMPT /CMPID=roc_ssl_v12 []
"APSDaemon"=C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [2014-07-31 43816]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-08-01 152392]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-08-21 959176]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2012-10-25 421888]
"IJNetworkScannerSelectorEX"=C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [2013-02-19 453736]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe [2014-10-07 843480]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
McAfee Security Scan Plus.lnk - C:\_OTM\MovedFiles\09112013_163548\C_Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2014-11-12 08:30:16 ----D---- C:\rsit
2014-11-10 17:54:04 ----D---- C:\ProgramData\CheapCoupon
2014-11-10 17:52:33 ----D---- C:\ProgramData\CoolSaleCoupon
2014-11-10 17:52:19 ----D---- C:\ProgramData\44ddf37e9357dff0
2014-11-10 15:13:16 ----D---- C:\Program Files (x86)\BlueStacks
2014-11-10 15:09:30 ----D---- C:\Users\Nikola\AppData\Roaming\Optimizer Pro
2014-11-10 15:06:36 ----D---- C:\Program Files (x86)\b2c1a4d4-496e-421e-bdd6-d933c230e3fb
2014-11-10 15:05:39 ----D---- C:\Program Files (x86)\globalUpdate
2014-11-10 15:05:30 ----D---- C:\Program Files (x86)\Shopp_Upe_1.8
2014-11-10 15:03:33 ----D---- C:\Program Files (x86)\Optimizer Pro
2014-11-04 21:58:36 ----D---- C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58:22 ----A---- C:\windows\SYSWOW64\CNHMCA.dll
2014-11-04 21:58:22 ----A---- C:\windows\SYSWOW64\CNC_BVL.dll
2014-11-04 21:56:39 ----D---- C:\windows\system32\STRING
2014-11-04 21:56:39 ----A---- C:\windows\SYSWOW64\CNMNPPM.DLL
2014-11-04 21:56:39 ----A---- C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56:39 ----A---- C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:54:35 ----A---- C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51:00 ----HD---- C:\ProgramData\CanonIJETV
2014-10-26 07:10:47 ----D---- C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09:27 ----HD---- C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52:22 ----D---- C:\ProgramData\CanonIJWSpt
2014-10-26 06:39:00 ----D---- C:\ProgramData\CanonIJPLM
2014-10-26 06:36:49 ----D---- C:\Program Files (x86)\Canon
2014-10-16 16:25:55 ----A---- C:\windows\system32\win32k.sys
2014-10-16 16:25:49 ----A---- C:\windows\SYSWOW64\mscorier.dll
2014-10-16 16:25:49 ----A---- C:\windows\system32\mscorier.dll
2014-10-16 16:25:48 ----A---- C:\windows\SYSWOW64\dfshim.dll
2014-10-16 16:25:48 ----A---- C:\windows\system32\dfshim.dll
2014-10-16 16:25:47 ----A---- C:\windows\SYSWOW64\mscories.dll
2014-10-16 16:25:47 ----A---- C:\windows\system32\mscories.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\mshtmled.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\jscript9diag.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\iernonce.dll
2014-10-16 16:25:29 ----A---- C:\windows\SYSWOW64\ieetwproxystub.dll
2014-10-16 16:25:28 ----A---- C:\windows\SYSWOW64\urlmon.dll
2014-10-16 16:25:28 ----A---- C:\windows\SYSWOW64\iedkcs32.dll
2014-10-16 16:25:28 ----A---- C:\windows\system32\iernonce.dll
2014-10-16 16:25:28 ----A---- C:\windows\system32\ie4uinit.exe
2014-10-16 16:25:27 ----A---- C:\windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25:27 ----A---- C:\windows\SYSWOW64\dxtmsft.dll
2014-10-16 16:25:27 ----A---- C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25:27 ----A---- C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25:26 ----A---- C:\windows\SYSWOW64\mshtml.dll
2014-10-16 16:25:26 ----A---- C:\windows\SYSWOW64\msfeeds.dll
2014-10-16 16:25:24 ----A---- C:\windows\SYSWOW64\iesetup.dll
2014-10-16 16:25:23 ----A---- C:\windows\system32\iedkcs32.dll
2014-10-16 16:25:22 ----A---- C:\windows\SYSWOW64\iertutil.dll
2014-10-16 16:25:22 ----A---- C:\windows\system32\urlmon.dll
2014-10-16 16:25:22 ----A---- C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25:21 ----A---- C:\windows\SYSWOW64\jsproxy.dll
2014-10-16 16:25:21 ----A---- C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25:20 ----A---- C:\windows\SYSWOW64\ieui.dll
2014-10-16 16:25:20 ----A---- C:\windows\SYSWOW64\dxtrans.dll
2014-10-16 16:25:20 ----A---- C:\windows\system32\msfeeds.dll
2014-10-16 16:25:20 ----A---- C:\windows\system32\dxtmsft.dll
2014-10-16 16:25:19 ----A---- C:\windows\SYSWOW64\ieframe.dll
2014-10-16 16:25:18 ----A---- C:\windows\system32\iesetup.dll
2014-10-16 16:25:16 ----A---- C:\windows\system32\iertutil.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\mshtmlmedia.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\jscript9.dll
2014-10-16 16:25:15 ----A---- C:\windows\SYSWOW64\ieUnatt.exe
2014-10-16 16:25:14 ----A---- C:\windows\SYSWOW64\vbscript.dll
2014-10-16 16:25:14 ----A---- C:\windows\SYSWOW64\ieapfltr.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\wininet.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\msrating.dll
2014-10-16 16:25:13 ----A---- C:\windows\SYSWOW64\MshtmlDac.dll
2014-10-16 16:25:13 ----A---- C:\windows\system32\jsproxy.dll
2014-10-16 16:25:11 ----A---- C:\windows\system32\ieui.dll
2014-10-16 16:25:11 ----A---- C:\windows\system32\dxtrans.dll
2014-10-16 16:25:10 ----A---- C:\windows\system32\ieframe.dll
2014-10-16 16:25:09 ----A---- C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25:09 ----A---- C:\windows\system32\mshtmled.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\jscript9diag.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\jscript9.dll
2014-10-16 16:25:08 ----A---- C:\windows\system32\ieUnatt.exe
2014-10-16 16:25:07 ----A---- C:\windows\system32\vbscript.dll
2014-10-16 16:25:07 ----A---- C:\windows\system32\ieapfltr.dll
2014-10-16 16:25:05 ----A---- C:\windows\system32\wininet.dll
2014-10-16 16:25:04 ----A---- C:\windows\system32\msrating.dll
2014-10-16 16:25:04 ----A---- C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25:02 ----A---- C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25:01 ----A---- C:\windows\system32\mshtml.dll
2014-10-16 16:23:35 ----A---- C:\windows\SYSWOW64\rastls.dll
2014-10-16 16:23:35 ----A---- C:\windows\system32\rastls.dll
2014-10-16 16:23:21 ----A---- C:\windows\SYSWOW64\mstscax.dll
2014-10-16 16:23:20 ----A---- C:\windows\system32\mstscax.dll
2014-10-16 16:23:18 ----A---- C:\windows\system32\mstsc.exe
2014-10-16 16:23:17 ----A---- C:\windows\system32\termsrv.dll
2014-10-16 16:23:16 ----A---- C:\windows\SYSWOW64\mstsc.exe
2014-10-16 16:23:14 ----A---- C:\windows\SYSWOW64\winsta.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\winsta.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\schannel.dll
2014-10-16 16:23:14 ----A---- C:\windows\system32\drivers\rdpwd.sys
2014-10-16 16:23:13 ----A---- C:\windows\SYSWOW64\schannel.dll
2014-10-16 16:23:13 ----A---- C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23:12 ----A---- C:\windows\SYSWOW64\aaclient.dll
2014-10-16 16:23:12 ----A---- C:\windows\system32\winlogon.exe
2014-10-16 16:23:11 ----A---- C:\windows\SYSWOW64\msv1_0.dll
2014-10-16 16:23:11 ----A---- C:\windows\system32\wdigest.dll
2014-10-16 16:23:11 ----A---- C:\windows\system32\msv1_0.dll
2014-10-16 16:23:10 ----A---- C:\windows\SYSWOW64\ncrypt.dll
2014-10-16 16:23:10 ----A---- C:\windows\system32\ncrypt.dll
2014-10-16 16:23:09 ----A---- C:\windows\SYSWOW64\TSpkg.dll
2014-10-16 16:23:09 ----A---- C:\windows\system32\TSpkg.dll
2014-10-16 16:23:08 ----A---- C:\windows\SYSWOW64\wdigest.dll
2014-10-16 16:23:08 ----A---- C:\windows\SYSWOW64\credssp.dll
2014-10-16 16:23:08 ----A---- C:\windows\system32\credssp.dll
2014-10-16 16:23:07 ----A---- C:\windows\system32\drivers\tssecsrv.sys
2014-10-16 16:22:24 ----A---- C:\windows\system32\packager.dll
2014-10-16 16:22:23 ----A---- C:\windows\SYSWOW64\packager.dll
======List of files/folders modified in the last 1 month======
2014-11-12 08:30:26 ----D---- C:\windows\Prefetch
2014-11-12 08:30:21 ----D---- C:\Program Files\trend micro
2014-11-12 08:29:28 ----D---- C:\windows\system32\catroot2
2014-11-12 08:29:28 ----D---- C:\windows\system32\catroot
2014-11-12 08:29:16 ----D---- C:\windows\Temp
2014-11-12 08:29:09 ----D---- C:\windows\winsxs
2014-11-12 08:20:26 ----D---- C:\windows\system32\config
2014-11-11 21:35:04 ----D---- C:\windows\SysWOW64
2014-11-11 21:35:01 ----A---- C:\windows\SYSWOW64\FlashPlayerApp.exe
2014-11-11 00:00:06 ----SHD---- C:\System Volume Information
2014-11-10 17:54:04 ----HD---- C:\ProgramData
2014-11-10 17:51:38 ----D---- C:\windows\Microsoft.NET
2014-11-10 15:18:36 ----SHD---- C:\windows\Installer
2014-11-10 15:18:35 ----RSD---- C:\windows\assembly
2014-11-10 15:16:41 ----D---- C:\Program Files (x86)
2014-11-10 15:14:24 ----D---- C:\ProgramData\BlueStacks
2014-11-10 15:09:40 ----D---- C:\windows\system32\Tasks
2014-11-10 15:09:36 ----D---- C:\windows\Tasks
2014-11-10 15:07:06 ----D---- C:\Program Files (x86)\7Go Games
2014-11-10 15:04:29 ----D---- C:\ProgramData\BlueStacksSetup
2014-11-09 19:53:15 ----D---- C:\windows\System32
2014-11-09 19:53:15 ----A---- C:\windows\system32\PerfStringBackup.INI
2014-11-09 19:53:14 ----D---- C:\windows\inf
2014-11-08 21:33:56 ----D---- C:\Users\Nikola\AppData\Roaming\newnext.me
2014-11-08 21:15:40 ----D---- C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58:26 ----RSD---- C:\windows\Media
2014-11-04 21:58:21 ----D---- C:\windows\twain_32
2014-11-04 21:55:16 ----HD---- C:\Program Files\CanonBJ
2014-11-04 21:55:15 ----D---- C:\windows\system32\DriverStore
2014-11-04 21:41:44 ----D---- C:\ProgramData\Lx_cats
2014-10-31 06:25:49 ----D---- C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40:05 ----D---- C:\filmy
2014-10-30 12:25:26 ----N---- C:\windows\system32\MpSigStub.exe
2014-10-28 20:30:40 ----HD---- C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30:37 ----HD---- C:\ProgramData\CanonBJ
2014-10-28 20:30:36 ----RD---- C:\Program Files
2014-10-28 20:30:33 ----D---- C:\windows\registration
2014-10-28 19:37:54 ----D---- C:\windows\system32\NDF
2014-10-28 19:31:53 ----D---- C:\windows\system32\wfp
2014-10-28 19:31:49 ----D---- C:\windows\system32\wbem
2014-10-28 19:31:49 ----D---- C:\Windows
2014-10-18 00:31:59 ----D---- C:\windows\rescache
2014-10-17 18:20:17 ----D---- C:\windows\system32\drivers
2014-10-17 18:17:04 ----D---- C:\windows\SYSWOW64\en-US
2014-10-17 18:17:04 ----D---- C:\Program Files\Internet Explorer
2014-10-17 18:17:03 ----D---- C:\windows\system32\en-US
2014-10-17 18:17:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-17 18:17:01 ----D---- C:\windows\SYSWOW64\cs-CZ
2014-10-17 18:17:01 ----D---- C:\windows\system32\cs-CZ
2014-10-17 18:16:06 ----D---- C:\ProgramData\Microsoft Help
2014-10-17 17:39:59 ----D---- C:\windows\system32\MRT
2014-10-17 16:24:46 ----A---- C:\windows\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\windows\system32\DRIVERS\AtiPcie.sys [2009-08-23 16440]
R0 LHDmgr;LHDmgr; C:\windows\System32\DRIVERS\LhdX64.sys [2010-01-15 39008]
R0 MpFilter;Microsoft Malware Protection Driver; C:\windows\system32\DRIVERS\MpFilter.sys [2014-07-17 269008]
R0 pciide;pciide; C:\windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 avgtp;avgtp; \??\C:\windows\system32\drivers\avgtpx64.sys [2012-08-30 31080]
R1 SCDEmu;SCDEmu; C:\windows\system32\drivers\SCDEmu.sys [2013-10-23 129944]
R1 vwififlt;Virtual WiFi Filter Driver; C:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [2014-10-07 122072]
R2 NisDrv;Microsoft Network Inspection System; C:\windows\system32\DRIVERS\NisDrvWFP.sys [2014-07-17 125584]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver; C:\windows\system32\DRIVERS\AcpiVpc.sys [2009-10-19 28176]
R3 amdkmdag;amdkmdag; C:\windows\system32\DRIVERS\atipmdag.sys [2010-03-03 6402560]
R3 amdkmdap;amdkmdap; C:\windows\system32\DRIVERS\atikmpag.sys [2010-03-03 188928]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\windows\system32\DRIVERS\athrx.sys [2009-11-06 1550848]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 btusbflt;Bluetooth USB Filter; C:\windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
R3 btwaudio;Bluetooth Audio Device Service; C:\windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
R3 btwavdt;Bluetooth AVDT Service; C:\windows\system32\DRIVERS\btwavdt.sys [2009-07-01 132648]
R3 btwl2cap;Bluetooth L2CAP Service; C:\windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
R3 btwrchid;btwrchid; C:\windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
R3 Cam5607;Lenovo EasyCamera ; C:\windows\System32\Drivers\BisonC07.sys [2010-04-20 1270896]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\windows\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RTKVHD64.sys [2010-04-27 2357024]
R3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller; C:\windows\system32\DRIVERS\L1C62x64.sys [2010-02-22 75304]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 SynTP;Synaptics TouchPad Driver; C:\windows\system32\DRIVERS\SynTP.sys [2010-01-07 302128]
R3 wdmirror;wdmirror; C:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11280]
S3 Bridge0;Bridge0; C:\windows\system32\drivers\WDBridge.sys [2009-07-16 79376]
S3 BTHPORT;Ovladač portu Bluetooth; C:\windows\System32\Drivers\BTHport.sys [2011-04-28 552960]
S3 fssfltr;FssFltr; C:\windows\system32\DRIVERS\fssfltr.sys [2013-02-05 57840]
S3 igfx;igfx; C:\windows\system32\DRIVERS\igdkmd64.sys [2009-06-10 6108416]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\windows\system32\DRIVERS\k57nd60a.sys [2009-06-10 270848]
S3 Netaapl;Apple Mobile Device Ethernet Service; C:\windows\system32\DRIVERS\netaapl64.sys [2013-07-25 23040]
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\windows\syswow64\drivers\pcdrndisuio.sys [2009-12-17 19456]
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0;PCDSRVC{A14E314B-3E985FDA-06000000}_0 - PCDR Kernel Mode Service Helper Driver; \??\f:\pcdoctor\pcdsrvc_x64.pkms []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\windows\System32\Drivers\RtsUStor.sys [2010-03-12 242720]
S3 TsUsbFlt;TsUsbFlt; C:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBAAPL64;Apple Mobile USB Driver; C:\windows\System32\Drivers\usbaapl64.sys [2012-12-13 54784]
S3 usbscan;Ovladač skeneru USB; C:\windows\system32\drivers\usbscan.sys [2013-07-03 42496]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WimFltr;WimFltr; C:\windows\system32\DRIVERS\wimfltr.sys [2008-08-06 151656]
S3 WinUsb;WinUsb; C:\windows\system32\DRIVERS\WinUsb.sys [2010-11-20 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 70e6ca8c;Optimizer Pro Crash Monitor; C:\windows\syswow64\rundll32.exe [2009-07-14 44544]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-09-12 64704]
R2 AMD External Events Utility;AMD External Events Utility; C:\windows\system32\atiesrxx.exe [2010-03-03 202752]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-06-12 43336]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [2014-10-07 388824]
R2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [2014-10-07 782040]
R2 btwdins;Bluetooth Service; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [2009-08-11 864032]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-05-14 140936]
R2 lxdi_device;lxdi_device; C:\windows\system32\lxdicoms.exe [2007-04-26 876976]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2014-08-22 23784]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [2013-03-10 186760]
R2 wgclbhvqtgnwlt;wgclbhvqtgnwlt; c:\windows\SysWOW64\HUAYNF~1.EXE [2012-04-15 102400]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-08-01 641352]
R3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2014-08-22 368624]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe [2014-10-07 409304]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 globalUpdate;globalUpdate Update Service (globalUpdate); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10 68608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S2 MsgPlusService;Messenger Plus! Service; C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe []
S2 ReadyComm.DirectRouter;ReadyComm.DirectRouter; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 vToolbarUpdater12.2.0;vToolbarUpdater12.2.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\12.2.0\ToolbarUpdater.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-11 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2010-03-18 44376]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-02-05 1512448]
S3 globalUpdatem;globalUpdate Update Service (globalUpdatem); C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-11-10 68608]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-18 107912]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2012-08-22 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\windows\system32\IEEtwCollector.exe [2014-09-19 111616]
S3 IGRS;IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [2009-07-14 38152]
S3 Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [2009-08-14 509192]
S3 Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [2009-09-22 579400]
S3 McComponentHostService;McAfee Security Scan Component Host Service; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2009-02-26 64856]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-04-07 119408]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-10-03 150600]
S3 PS_MDP;ReadyComm Presentation Space Helper Service; C:\windows\System32\IgrsSvcs.exe -k IgrsSvcs []
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\windows\system32\Wat\WatAdminSvc.exe [2011-05-08 1255736]
S4 NetMsmqActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
-----------------EOF-----------------
Re: Zavirovaný ntb
Dobre dopoledne Vam preju 
Aktualizujte
Odinstalujte McAfee Security Scan
V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).
Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/


- Adobe Flash - http://get.adobe.com/flashplayer/
- Adobe Reader - spustte Adobe Reader a nahore klik na Napoveda -> Zkontrolovat aktualizace



- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Clean
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
Adobe reader - aktualni verze
Adobe flash - aktualizuje se automaticky v chrome(?)
Mcafee je davno odinstalovan - zustali nejake soubory v pc(?)
Moc se ve windowsech nevyznam, pouzivam jiny operacni system
log:
# AdwCleaner v4.101 - Report created 12/11/2014 at 09:25:13
# Updated 09/11/2014 by Xplode
# Database : 2014-11-11.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Nikola - NIKOLA-PC
# Running from : C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : 70e6ca8c
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : vToolbarUpdater12.2.0
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\wincert
Folder Deleted : C:\ProgramData\CheapCoupon
Folder Deleted : C:\ProgramData\CoolSaleCoupon
Folder Deleted : C:\ProgramData\44ddf37e9357dff0
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Folder Deleted : C:\Program Files (x86)\7Go Games
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Optimizer Pro
Folder Deleted : C:\Program Files (x86)\RichMediaViewV1
Folder Deleted : C:\Program Files (x86)\Speed Analysis 3
Folder Deleted : C:\Program Files (x86)\Shopp_Upe_1.8
Folder Deleted : C:\Users\Nikola\AppData\Local\genienext
Folder Deleted : C:\Users\Nikola\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Nikola\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Nikola\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Nikola\AppData\Local\torch
Folder Deleted : C:\Users\Nikola\AppData\Local\Temp\mt_ffx
Folder Deleted : C:\Users\Nikola\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Optimizer Pro
Folder Deleted : C:\Users\Nikola\AppData\Roaming\SpeedAnalysis3
Folder Deleted : C:\Users\Nikola\Documents\Optimizer Pro
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\speedanalysis03@SpeedAnalysis.com
[!] Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\50db678457b16@50db678457b4f.com
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\info@thebflix.com
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\chang.gibbons98@aol.com
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdgpjclefcppbhifgmbncakhhphkggdb
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpggnebiiidmpnljdeoaihefneahlnln
Folder Deleted : C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpggnebiiidmpnljdeoaihefneahlnln
File Deleted : C:\Users\Nikola\daemonprocess.txt
File Deleted : C:\Users\Nikola\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Nikola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
File Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\smartbar.xml
File Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\user.js
***** [ Scheduled Tasks ] *****
Task Deleted : AmiUpdXp
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : Optimizer Pro Schedule
Task Deleted : PC Performer
Task Deleted : PC Performer_DEFAULT
Task Deleted : PC Performer_UPDATES
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-1
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5_user
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bdgpjclefcppbhifgmbncakhhphkggdb
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bfcpnihmbfoaeoakalclfalkdepgiaje
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hgojaaaiddhmiiakpejiklijbalpckih
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mbmpjbkgemhgalmeiigcdljkccfcafoj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject.1
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.Navbar
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.Navbar.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Key Deleted : HKLM\SOFTWARE\Classes\CoolSaleCoupon.CoolSaleCoupon
Key Deleted : HKLM\SOFTWARE\Classes\CoolSaleCoupon.CoolSaleCoupon.9
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{58B849FB-ECBE-4F1B-BEE0-2DC418CF68F7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622212282}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655215582}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666216682}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{0771C34F-730F-4535-AD4C-37B74D27188E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{15998F3C-BBA9-476D-8FC2-09BE9E3B8751}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D88E0FD9-31EB-48EF-BC89-35EBCE0E813C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644214482}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{58B849FB-ECBE-4F1B-BEE0-2DC418CF68F7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611211182}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622212282}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655215582}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666216682}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5C2A072F-CF8A-47B6-B95B-6266316D287E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C1E41CE9-B9D6-4CD6-8D14-422DA8FAF33B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DA4CA344-648A-49E0-96C5-EE8194031ABE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\torch
Key Deleted : HKCU\Software\yuna software
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Shopp_Upe_1.8
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\MediaBuzzV1
Key Deleted : HKLM\SOFTWARE\MediaPlayerV1
Key Deleted : HKLM\SOFTWARE\MediaViewerV1
Key Deleted : HKLM\SOFTWARE\MediaViewV1
Key Deleted : HKLM\SOFTWARE\MediaWatchV1
Key Deleted : HKLM\SOFTWARE\torch
Key Deleted : HKLM\SOFTWARE\yuna software
Key Deleted : HKLM\SOFTWARE\Shopp_Upe_1.8
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wxDownload Fast_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0C516764-8CFC-C2FE-7BB0-A50A646E4DCD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shopp_Upe_1.8
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wxDownload Fast_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17344
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v28.0 (cs)
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.50db678457bb5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"su[...]
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.autoRvrt", "false");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.dfltSrch", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.dnsErr", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hmpg", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hmpgUrl", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hpOld0", "");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.kw_url", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.newTab", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.newTabUrl", "hxxp://search.creativetoolbars.com/?src=nt&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.rvrt", "false");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.srchPrvdr", "Search the web (CT)");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Search the web (CT)");
-\\ Google Chrome v38.0.2125.111
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bdgpjclefcppbhifgmbncakhhphkggdb
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : dlfienamagdnkekbbbocojppncdambda
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : lifbcibllhkdhoafpjfnlhfpfgnpldfl
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bpggnebiiidmpnljdeoaihefneahlnln
[C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bpggnebiiidmpnljdeoaihefneahlnln
*************************
AdwCleaner[R0].txt - [15709 octets] - [10/09/2013 13:20:03]
AdwCleaner[R1].txt - [24784 octets] - [12/11/2014 09:21:05]
AdwCleaner[S0].txt - [15524 octets] - [10/09/2013 13:21:41]
AdwCleaner[S1].txt - [24262 octets] - [12/11/2014 09:25:13]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [24323 octets] ##########
Adobe flash - aktualizuje se automaticky v chrome(?)
Mcafee je davno odinstalovan - zustali nejake soubory v pc(?)
Moc se ve windowsech nevyznam, pouzivam jiny operacni system
log:
# AdwCleaner v4.101 - Report created 12/11/2014 at 09:25:13
# Updated 09/11/2014 by Xplode
# Database : 2014-11-11.2 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Nikola - NIKOLA-PC
# Running from : C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
# Option : Clean
***** [ Services ] *****
Service Deleted : 70e6ca8c
[#] Service Deleted : globalUpdate
[#] Service Deleted : globalUpdatem
[#] Service Deleted : vToolbarUpdater12.2.0
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\wincert
Folder Deleted : C:\ProgramData\CheapCoupon
Folder Deleted : C:\ProgramData\CoolSaleCoupon
Folder Deleted : C:\ProgramData\44ddf37e9357dff0
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Folder Deleted : C:\Program Files (x86)\7Go Games
Folder Deleted : C:\Program Files (x86)\globalUpdate
Folder Deleted : C:\Program Files (x86)\Optimizer Pro
Folder Deleted : C:\Program Files (x86)\RichMediaViewV1
Folder Deleted : C:\Program Files (x86)\Speed Analysis 3
Folder Deleted : C:\Program Files (x86)\Shopp_Upe_1.8
Folder Deleted : C:\Users\Nikola\AppData\Local\genienext
Folder Deleted : C:\Users\Nikola\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Nikola\AppData\Local\Mobogenie
Folder Deleted : C:\Users\Nikola\AppData\Local\SwvUpdater
Folder Deleted : C:\Users\Nikola\AppData\Local\torch
Folder Deleted : C:\Users\Nikola\AppData\Local\Temp\mt_ffx
Folder Deleted : C:\Users\Nikola\AppData\Roaming\newnext.me
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Optimizer Pro
Folder Deleted : C:\Users\Nikola\AppData\Roaming\SpeedAnalysis3
Folder Deleted : C:\Users\Nikola\Documents\Optimizer Pro
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\speedanalysis03@SpeedAnalysis.com
[!] Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\speedanalysis03@SpeedAnalysis.com.xpi
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\50db678457b16@50db678457b4f.com
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\info@thebflix.com
Folder Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\chang.gibbons98@aol.com
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdgpjclefcppbhifgmbncakhhphkggdb
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlfienamagdnkekbbbocojppncdambda
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Folder Deleted : C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpggnebiiidmpnljdeoaihefneahlnln
Folder Deleted : C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpggnebiiidmpnljdeoaihefneahlnln
File Deleted : C:\Users\Nikola\daemonprocess.txt
File Deleted : C:\Users\Nikola\AppData\Local\Temp\Uninstall.exe
File Deleted : C:\Users\Nikola\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iLivid.lnk
File Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\smartbar.xml
File Deleted : C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\user.js
***** [ Scheduled Tasks ] *****
Task Deleted : AmiUpdXp
Task Deleted : globalUpdateUpdateTaskMachineCore
Task Deleted : globalUpdateUpdateTaskMachineUA
Task Deleted : Optimizer Pro Schedule
Task Deleted : PC Performer
Task Deleted : PC Performer_DEFAULT
Task Deleted : PC Performer_UPDATES
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-1
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5_user
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6
Task Deleted : 7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bdgpjclefcppbhifgmbncakhhphkggdb
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\bfcpnihmbfoaeoakalclfalkdepgiaje
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\gjajpkikblccgefaibcafkfbanllpefi
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\hgojaaaiddhmiiakpejiklijbalpckih
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\kiplfnciaokpcennlkldkdaeaaomamof
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\mbmpjbkgemhgalmeiigcdljkccfcafoj
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [NextLive]
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Key Deleted : HKLM\SOFTWARE\Classes\*\shell\filescout
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.BackgroundHostObject.1
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.Navbar
Key Deleted : HKLM\SOFTWARE\Classes\Speed Analysis 3.Navbar.1
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd
Key Deleted : HKLM\SOFTWARE\Classes\Updater.AmiUpd.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Key Deleted : HKLM\SOFTWARE\Classes\CoolSaleCoupon.CoolSaleCoupon
Key Deleted : HKLM\SOFTWARE\Classes\CoolSaleCoupon.CoolSaleCoupon.9
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{58B849FB-ECBE-4F1B-BEE0-2DC418CF68F7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622212282}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655215582}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666216682}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{0771C34F-730F-4535-AD4C-37B74D27188E}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{15998F3C-BBA9-476D-8FC2-09BE9E3B8751}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D88E0FD9-31EB-48EF-BC89-35EBCE0E813C}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644214482}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{58B849FB-ECBE-4F1B-BEE0-2DC418CF68F7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{ACE0D5AB-50C8-4052-BD02-977569E56291}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611211182}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622212282}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{06E50566-0AB7-431C-841D-62794727DAF9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{26E7211D-0650-43CF-8498-4C81E83AEAAA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{2D017725-74A0-4513-913D-2939ADF6D0F3}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{458BD324-E5D0-412C-954D-EDFD69A59ED9}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{93CF54F5-CFAA-4440-B588-8ED0DFAD5C21}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9ADA5C62-B227-45A9-9D77-E5609A43E943}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B5445928-B77D-474B-84F6-6F1323CA5701}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BE6C7021-0352-4A7E-8A5B-46126353049E}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D3BC53E7-0437-4C97-90EE-2CD6FF47FB14}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D94BA844-0355-4F02-97F2-6856CD94FE66}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655215582}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666216682}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF103732-4528-4322-AA8B-F7849AB7776B}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a4feea9e-7905-4969-8886-69b16d909c6b}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611211182}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{5C2A072F-CF8A-47B6-B95B-6266316D287E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{C1E41CE9-B9D6-4CD6-8D14-422DA8FAF33B}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DA4CA344-648A-49E0-96C5-EE8194031ABE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2423}
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\torch
Key Deleted : HKCU\Software\yuna software
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Shopp_Upe_1.8
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\MediaBuzzV1
Key Deleted : HKLM\SOFTWARE\MediaPlayerV1
Key Deleted : HKLM\SOFTWARE\MediaViewerV1
Key Deleted : HKLM\SOFTWARE\MediaViewV1
Key Deleted : HKLM\SOFTWARE\MediaWatchV1
Key Deleted : HKLM\SOFTWARE\torch
Key Deleted : HKLM\SOFTWARE\yuna software
Key Deleted : HKLM\SOFTWARE\Shopp_Upe_1.8
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wxDownload Fast_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0C516764-8CFC-C2FE-7BB0-A50A646E4DCD}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shopp_Upe_1.8
Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wxDownload Fast_is1
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17344
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v28.0 (cs)
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.50db678457bb5.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"su[...]
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.autoRvrt", "false");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.dfltSrch", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.dnsErr", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hmpg", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hmpgUrl", "hxxp://search.creativetoolbars.com/?src=hp&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.hpOld0", "");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.kw_url", "hxxp://search.creativetoolbars.com/results?src=tb&id=smartbar&g=&q=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.newTab", true);
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.newTabUrl", "hxxp://search.creativetoolbars.com/?src=nt&id=smartbar&g=");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.rvrt", "false");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("extensions.smartbar.srchPrvdr", "Search the web (CT)");
[rrrs58j5.default\prefs.js] - Line Deleted : user_pref("browser.search.selectedEngine", "Search the web (CT)");
-\\ Google Chrome v38.0.2125.111
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bdgpjclefcppbhifgmbncakhhphkggdb
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : dlfienamagdnkekbbbocojppncdambda
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : lifbcibllhkdhoafpjfnlhfpfgnpldfl
[C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bpggnebiiidmpnljdeoaihefneahlnln
[C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\preferences] - Deleted [Extension] : bpggnebiiidmpnljdeoaihefneahlnln
*************************
AdwCleaner[R0].txt - [15709 octets] - [10/09/2013 13:20:03]
AdwCleaner[R1].txt - [24784 octets] - [12/11/2014 09:21:05]
AdwCleaner[S0].txt - [15524 octets] - [10/09/2013 13:21:41]
AdwCleaner[S1].txt - [24262 octets] - [12/11/2014 09:25:13]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [24323 octets] ##########
Re: Zavirovaný ntb



- spustte jako spravce
- do velkeho okna zkopirujte script uvedeny nize
- kliknete na Run script
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\zoek-results.log) - vlozte mi jej do pristi odpovedi
Kód: Vybrat vše
autoclean; emptyclsid; iedefaults; FFdefaults; CHRdefaults; emptyalltemp; resethosts;
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
trvalo to dele nez jsem cekal 
Zoek.exe v5.0.0.0 Updated 11-November-2014
Tool run by Nikola on st 12.11.2014 at 9:47:02,48.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Nikola\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
12.11.2014 9:52:17 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6759719C-E0A3-4DD9-9187-D5870C44D986} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{1392B8D2-5C05-419F-A8F6-B9F15A596612} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0FB6A909-6086-458F-BD92-1F8EE10042A0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{944FEDFD-C4FD-441D-8275-9C651A9FFBDE} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{FF103732-4528-4322-AA8B-F7849AB7776B} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{faa68d77-52a4-4135-88f8-d9e46a19ed26} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{c2e1f78c-2243-4bec-bb3d-fd4302698850} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{35c2c9c6-adea-41f5-8b1b-ca3930fa0a3e} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{ae60a102-145b-41ec-b8c0-dcb5b0486b10} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0d1fa430-ca47-4d15-8d50-cc5220ccda0f} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{a77bb565-f68d-4dc4-b063-3725317f6cf1} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0e283daa-738b-4df1-be75-14bc282c2580} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611211182} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha5009.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1655.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha3743.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha6152.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home427.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaBuzzV1mode4070.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release2297.net deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
Added to C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\prefs.js:
user_pref("browser.search.defaulturl", "");
user_pref("browser.search.selectedEngine,S", "");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default\prefs.js:
Added to C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default\prefs.js:
Added to C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
user.js not found
---- Lines isearch removed from prefs.js ----
user_pref("weboftrust.search.avg.url", "^http(s)?\\:\\/\\/isearch\\.avg\\.com\\/search\\?");
---- Lines StatusWinks removed from prefs.js ----
user_pref("extensions.statuswinks@StatusWinks.id", "\"aca0982a-f78f-8f25-d9c6-f16064fbbd21\"");
user_pref("extensions.statuswinks@StatusWinks.mzID", "53");
user_pref("extensions.statuswinks@StatusWinks.uuid", "\"57a8400f-a92e-11e2-a367-0025901ef77c\"");
---- Lines ask.com removed from prefs.js ----
user_pref("weboftrust.search.ask.display", "Ask.com Web Search");
---- Lines specialsavings removed from prefs.js ----
user_pref("extensions.SpecialSavings@SpecialSavings.com.id", "\"43477a28-f5e4-9b9a-fe80-42870670558d\"");
user_pref("extensions.SpecialSavings@SpecialSavings.com.mzID", "65");
user_pref("extensions.SpecialSavings@SpecialSavings.com.uuid", "\"57a20394-a92e-11e2-a367-0025901ef77c\"");
---- Lines SpeedAnalysis modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@RichMediaViewV1release2297.net\":{\"descriptor\":\"C:\\\\Prog
---- Lines extensions.50db678457bb5 removed from prefs.js ----
user_pref("extensions.50db678457bb5.epoch", "1412530928");
user_pref("extensions.50db678457bb5.url", "http://sunfuun.com/sync/?ext=wxd&pid=24 ... 0&ssd=0&xn
---- Lines ext@RichMediaViewV1release2297.net modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@RichMediaViewV1release2297.net\":{\"descriptor\":\"C:\\\\Prog
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
==== Deleting Files \ Folders ======================
C:\Users\Nikola\AppData\Local\2678 deleted
C:\PROGRA~3\WoW Worldwide Software LTD deleted
C:\Users\Nikola\.android deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\ipod service deleted
C:\PROGRA~2\b2c1a4d4-496e-421e-bdd6-d933c230e3fb deleted
C:\PROGRA~2\WxDownload deleted
C:\PROGRA~2\wxDownload Fast deleted
C:\MuziicSetup.exe deleted
C:\PinnacleStudio_Trial_V15.exe deleted
C:\Users\Nikola\AppData\Roaming\ICQ Search deleted
C:\PROGRA~3\SPLDE33.tmp deleted
C:\PROGRA~3\ICQ deleted
C:\Users\Nikola\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxDownload deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxDownload Fast deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Users\Nikola\Downloads\iLividSetup-r834-n-bc.exe deleted
C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\windows\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0}.job deleted
C:\windows\SysNative\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0} deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\extensions\staged deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\ICQToolbarData deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\staged deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks deleted
"C:\Users\Nikola\AppData\Local\{03C6866D-80F5-4687-98A2-D32045DA89AC}" deleted
"C:\Users\Nikola\AppData\Local\{061D307D-4F20-41F2-88D9-DC40F868E504}" deleted
"C:\Users\Nikola\AppData\Local\{31150F91-0C3D-45D9-8E11-9D3DE79F6950}" deleted
"C:\Users\Nikola\AppData\Local\{493C997E-E343-4589-BE07-493C127C0725}" deleted
"C:\Users\Nikola\AppData\Local\{70F570C7-425B-4C20-9110-A0F50DB071A5}" deleted
"C:\Users\Nikola\AppData\Local\{A04DCE8C-ACBE-4E68-B068-189332DDD1F2}" deleted
"C:\Users\Nikola\AppData\Local\{CB623E65-EAA4-4ABD-934D-6ADDD2A1C199}" deleted
"C:\Users\Nikola\AppData\Local\{D87D7A30-2C6C-4310-80EF-488B95F1828E}" deleted
"C:\Users\Nikola\AppData\Local\{E40F5DAA-58E6-4BE8-83AD-886B857CCCA4}" deleted
"C:\Users\Nikola\AppData\Local\{EFC0E5D3-9D96-4567-9F08-7E843242C4D9}" deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
- Undetermined - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Fotofox - %ProfilePath%\extensions\fotofox@mozilla.com.xpi
- FREE MP3 Search - %ProfilePath%\extensions\search@org-com.eu.xpi
- Black Skin - %ProfilePath%\extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi
ProfilePath: C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- Nvu default - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
5B4DA1113F240C3F06FFF9D52761528B - C:\Picasa3\npPicasa3.dll - Picasa
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
djpcdiikhfpaacohicgchhdpfdkfogid - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3743\ch\MediaViewV1alpha3743.crx[]
dlkdaocijlbeikjlajnlhedajkjeafah - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1655\ch\MediaViewerV1alpha1655.crx[]
eehjfjhpomfeibkklbmbkfomlpofdgga - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6152\ch\MediaViewV1alpha6152.crx[]
jfmjfhklogoienhpfnppmbcbjfjnkonk - No path found[]
jlfihafpijfdgmojeeigcldgchhojpfp - C:\Program Files (x86)\BFlix\BFlix.crx[]
kdjngnlnjejlaajmcopljhegmpgdembk - C:\ProgramData\wxDownload\kdjngnlnjejlaajmcopljhegmpgdembk.crx[]
njejhlajmimhajkdbbaokcegnjahmajp - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home427\ch\MediaWatchV1home427.crx[]
nnmbipmkefkcbifnbhbfmconkjjdhkco - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4070\ch\MediaBuzzV1mode4070.crx[]
Bflix extension - Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp
Chainlove Countdown Timer - Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljppcglljemjablfhgjdhndlpallobpl
==== Chromium Startpages ======================
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/",
"startup_urls": [ "http://www.searchnu.com/423" ],
==== Chromium Fix ======================
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_click.dealshark.com_0.localstorage deleted successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_click.dealshark.com_0.localstorage-journal deleted successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage-journal deleted successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp deleted successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljppcglljemjablfhgjdhndlpallobpl deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Search_URL"="http://www.google.com/ie"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{DA4CA344-648A-49E0-96C5-EE8194031ABE}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DA4CA344-648A-49E0-96C5-EE8194031ABE}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{17D4BBA2-67AF-4BCF-BF09-ECBA5D780A25} Google Url="http://www.google.com/search?q={searchT ... f8&oe=utf8"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... QN_csCZ467"
==== Reset Google Chrome ======================
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{05AAB3C6-198A-13B4-A6C0-6F72D0D7DB5D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{82778A7A-5228-7477-969C-1A0A5994A88C} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0E10101D-5784-6E2B-B982-C0079A497C1E} deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\djpcdiikhfpaacohicgchhdpfdkfogid deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dlkdaocijlbeikjlajnlhedajkjeafah deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eehjfjhpomfeibkklbmbkfomlpofdgga deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kdjngnlnjejlaajmcopljhegmpgdembk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\njejhlajmimhajkdbbaokcegnjahmajp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nnmbipmkefkcbifnbhbfmconkjjdhkco deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RichMediaViewV1release2297 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Nikola\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Nikola\AppData\Local\Mozilla\Firefox\Profiles\rrrs58j5.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=491 folders=76 35748809 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\Next\AppData\Local\Temp emptied successfully
C:\Users\Nikola\AppData\Local\Temp will be emptied at reboot
C:\windows\SysNative\config\systemprofile\AppData\Local\Temp emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Nikola\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 12.11.2014 at 10:30:50,64 ======================

Zoek.exe v5.0.0.0 Updated 11-November-2014
Tool run by Nikola on st 12.11.2014 at 9:47:02,48.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Nikola\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
12.11.2014 9:52:17 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6759719C-E0A3-4DD9-9187-D5870C44D986} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{1392B8D2-5C05-419F-A8F6-B9F15A596612} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0FB6A909-6086-458F-BD92-1F8EE10042A0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{9D717F81-9148-4F12-8568-69135F087DB0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{944FEDFD-C4FD-441D-8275-9C651A9FFBDE} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{A66261FC-B82E-4EC7-9F6D-C2F36B871DF0} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{FF103732-4528-4322-AA8B-F7849AB7776B} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{faa68d77-52a4-4135-88f8-d9e46a19ed26} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{c2e1f78c-2243-4bec-bb3d-fd4302698850} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{35c2c9c6-adea-41f5-8b1b-ca3930fa0a3e} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{ae60a102-145b-41ec-b8c0-dcb5b0486b10} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0d1fa430-ca47-4d15-8d50-cc5220ccda0f} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{a77bb565-f68d-4dc4-b063-3725317f6cf1} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{0e283daa-738b-4df1-be75-14bc282c2580} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110611211182} deleted successfully
HKEY_USERS\S-1-5-21-2772758291-4078256221-3500050187-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaPlayerV1alpha5009.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewerV1alpha1655.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha3743.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaViewV1alpha6152.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaWatchV1home427.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@MediaBuzzV1mode4070.net deleted successfully
HKEY_LOCAL_MACHINE\software\Wow6432Node\mozilla\Firefox\extensions\ext@RichMediaViewV1release2297.net deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.seznam.cz/");
Added to C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\prefs.js:
user_pref("browser.search.defaulturl", "");
user_pref("browser.search.selectedEngine,S", "");
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default\prefs.js:
Added to C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
Deleted from C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default\prefs.js:
Added to C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
user.js not found
---- Lines isearch removed from prefs.js ----
user_pref("weboftrust.search.avg.url", "^http(s)?\\:\\/\\/isearch\\.avg\\.com\\/search\\?");
---- Lines StatusWinks removed from prefs.js ----
user_pref("extensions.statuswinks@StatusWinks.id", "\"aca0982a-f78f-8f25-d9c6-f16064fbbd21\"");
user_pref("extensions.statuswinks@StatusWinks.mzID", "53");
user_pref("extensions.statuswinks@StatusWinks.uuid", "\"57a8400f-a92e-11e2-a367-0025901ef77c\"");
---- Lines ask.com removed from prefs.js ----
user_pref("weboftrust.search.ask.display", "Ask.com Web Search");
---- Lines specialsavings removed from prefs.js ----
user_pref("extensions.SpecialSavings@SpecialSavings.com.id", "\"43477a28-f5e4-9b9a-fe80-42870670558d\"");
user_pref("extensions.SpecialSavings@SpecialSavings.com.mzID", "65");
user_pref("extensions.SpecialSavings@SpecialSavings.com.uuid", "\"57a20394-a92e-11e2-a367-0025901ef77c\"");
---- Lines SpeedAnalysis modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@RichMediaViewV1release2297.net\":{\"descriptor\":\"C:\\\\Prog
---- Lines extensions.50db678457bb5 removed from prefs.js ----
user_pref("extensions.50db678457bb5.epoch", "1412530928");
user_pref("extensions.50db678457bb5.url", "http://sunfuun.com/sync/?ext=wxd&pid=24 ... 0&ssd=0&xn
---- Lines ext@RichMediaViewV1release2297.net modified from prefs.js ----
user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"ext@RichMediaViewV1release2297.net\":{\"descriptor\":\"C:\\\\Prog
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
ProfilePath: C:\Users\Nikola\AppData\Roaming\PC-Doctor, Inc\Lenovo China Field Service Solution\Profiles\6pwnpocx.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs_12.11.2014_1014_.backup
==== Deleting Files \ Folders ======================
C:\Users\Nikola\AppData\Local\2678 deleted
C:\PROGRA~3\WoW Worldwide Software LTD deleted
C:\Users\Nikola\.android deleted
C:\PROGRA~2\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\PROGRA~2\ipod service deleted
C:\PROGRA~2\b2c1a4d4-496e-421e-bdd6-d933c230e3fb deleted
C:\PROGRA~2\WxDownload deleted
C:\PROGRA~2\wxDownload Fast deleted
C:\MuziicSetup.exe deleted
C:\PinnacleStudio_Trial_V15.exe deleted
C:\Users\Nikola\AppData\Roaming\ICQ Search deleted
C:\PROGRA~3\SPLDE33.tmp deleted
C:\PROGRA~3\ICQ deleted
C:\Users\Nikola\AppData\Local\cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxDownload deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\wxDownload Fast deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk deleted
C:\Users\Nikola\Downloads\iLividSetup-r834-n-bc.exe deleted
C:\windows\sysWoW64\config\systemprofile\AppData\LocalLow\Application Updater deleted
C:\windows\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0}.job deleted
C:\windows\SysNative\tasks\OptimizerProUpdaterTask{A19EDBFF-B98A-4535-80BE-A02E1217D8F0} deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\Next\AppData\Roaming\Mozilla\Firefox\Profiles\64acrto5.default\extensions\staged deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\ICQToolbarData deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\staged deleted
C:\Users\Nikola\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks deleted
"C:\Users\Nikola\AppData\Local\{03C6866D-80F5-4687-98A2-D32045DA89AC}" deleted
"C:\Users\Nikola\AppData\Local\{061D307D-4F20-41F2-88D9-DC40F868E504}" deleted
"C:\Users\Nikola\AppData\Local\{31150F91-0C3D-45D9-8E11-9D3DE79F6950}" deleted
"C:\Users\Nikola\AppData\Local\{493C997E-E343-4589-BE07-493C127C0725}" deleted
"C:\Users\Nikola\AppData\Local\{70F570C7-425B-4C20-9110-A0F50DB071A5}" deleted
"C:\Users\Nikola\AppData\Local\{A04DCE8C-ACBE-4E68-B068-189332DDD1F2}" deleted
"C:\Users\Nikola\AppData\Local\{CB623E65-EAA4-4ABD-934D-6ADDD2A1C199}" deleted
"C:\Users\Nikola\AppData\Local\{D87D7A30-2C6C-4310-80EF-488B95F1828E}" deleted
"C:\Users\Nikola\AppData\Local\{E40F5DAA-58E6-4BE8-83AD-886B857CCCA4}" deleted
"C:\Users\Nikola\AppData\Local\{EFC0E5D3-9D96-4567-9F08-7E843242C4D9}" deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
- Undetermined - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff
- WOT - %ProfilePath%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Fotofox - %ProfilePath%\extensions\fotofox@mozilla.com.xpi
- FREE MP3 Search - %ProfilePath%\extensions\search@org-com.eu.xpi
- Black Skin - %ProfilePath%\extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi
ProfilePath: C:\Users\Nikola\AppData\Roaming\Nvu\Profiles\aaxzd9c0.default
- Undetermined - %ProfilePath%\extensions\installed-extensions.txt
- Nvu default - %ProfilePath%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Skype Click to Call - %AppDir%\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
5B4DA1113F240C3F06FFF9D52761528B - C:\Picasa3\npPicasa3.dll - Picasa
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted
==== Chromium Look ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
djpcdiikhfpaacohicgchhdpfdkfogid - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha3743\ch\MediaViewV1alpha3743.crx[]
dlkdaocijlbeikjlajnlhedajkjeafah - C:\Program Files (x86)\MediaViewerV1\MediaViewerV1alpha1655\ch\MediaViewerV1alpha1655.crx[]
eehjfjhpomfeibkklbmbkfomlpofdgga - C:\Program Files (x86)\MediaViewV1\MediaViewV1alpha6152\ch\MediaViewV1alpha6152.crx[]
jfmjfhklogoienhpfnppmbcbjfjnkonk - No path found[]
jlfihafpijfdgmojeeigcldgchhojpfp - C:\Program Files (x86)\BFlix\BFlix.crx[]
kdjngnlnjejlaajmcopljhegmpgdembk - C:\ProgramData\wxDownload\kdjngnlnjejlaajmcopljhegmpgdembk.crx[]
njejhlajmimhajkdbbaokcegnjahmajp - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home427\ch\MediaWatchV1home427.crx[]
nnmbipmkefkcbifnbhbfmconkjjdhkco - C:\Program Files (x86)\MediaBuzzV1\MediaBuzzV1mode4070\ch\MediaBuzzV1mode4070.crx[]
Bflix extension - Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp
Chainlove Countdown Timer - Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljppcglljemjablfhgjdhndlpallobpl
==== Chromium Startpages ======================
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.seznam.cz/",
"startup_urls": [ "http://www.searchnu.com/423" ],
==== Chromium Fix ======================
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_click.dealshark.com_0.localstorage deleted successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_click.dealshark.com_0.localstorage-journal deleted successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_isearch.avg.com_0.localstorage-journal deleted successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp deleted successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljppcglljemjablfhgjdhndlpallobpl deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"
"Default_Search_URL"="http://www.google.com/ie"
"Use Search Asst"="yes"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
@="http://www.google.com/search?q=%s"
"Default"="http://www.bing.com/search?q={searchTerms}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{DA4CA344-648A-49E0-96C5-EE8194031ABE}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DA4CA344-648A-49E0-96C5-EE8194031ABE}] not found
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.google.com"
"Use Search Asst"="no"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl]
"(Default)"="http://search.msn.com/results.asp?q=%s"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Search]
"SearchAssistant"="http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{17D4BBA2-67AF-4BCF-BF09-ECBA5D780A25} Google Url="http://www.google.com/search?q={searchT ... f8&oe=utf8"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... QN_csCZ467"
==== Reset Google Chrome ======================
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\preferences was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Preferences was reset successfully
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Web Data was reset successfully
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{05AAB3C6-198A-13B4-A6C0-6F72D0D7DB5D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{82778A7A-5228-7477-969C-1A0A5994A88C} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{0E10101D-5784-6E2B-B982-C0079A497C1E} deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\djpcdiikhfpaacohicgchhdpfdkfogid deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\dlkdaocijlbeikjlajnlhedajkjeafah deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\eehjfjhpomfeibkklbmbkfomlpofdgga deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\jlfihafpijfdgmojeeigcldgchhojpfp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\kdjngnlnjejlaajmcopljhegmpgdembk deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\njejhlajmimhajkdbbaokcegnjahmajp deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\nnmbipmkefkcbifnbhbfmconkjjdhkco deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RichMediaViewV1release2297 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeriFaceManager deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Nikola\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Nikola\AppData\Local\Mozilla\Firefox\Profiles\rrrs58j5.default\Cache emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Next\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=491 folders=76 35748809 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\Next\AppData\Local\Temp emptied successfully
C:\Users\Nikola\AppData\Local\Temp will be emptied at reboot
C:\windows\SysNative\config\systemprofile\AppData\Local\Temp emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Nikola\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on st 12.11.2014 at 10:30:50,64 ======================
Re: Zavirovaný ntb



Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by Nikola (administrator) on NIKOLA-PC on 12-11-2014 11:37:52
Running from C:\Users\Nikola\Desktop
Loaded Profile: Nikola (Available profiles: Nikola & Next & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
( Company (R)) C:\Windows\SysWOW64\HUAYNF~1.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
( ) C:\Windows\System32\lxdicoms.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
(Lexmark) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1894696 2010-01-07] (Synaptics Incorporated)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [lxdimon.exe] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [435120 2007-05-07] ()
HKLM\...\Run: [lxdiamon] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [20480 2007-03-05] (Lexmark)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [FaxCenterServer] => C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [312240 2007-05-07] ()
HKLM-x32\...\Run: [Freecorder FLV Service] => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe"
HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480 2014-10-07] (BlueStack Systems, Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-02]
FF Extension: Seznam lištička - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-28]
FF Extension: Fotofox - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\fotofox@mozilla.com.xpi [2012-06-04]
FF Extension: FREE MP3 Search - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\search@org-com.eu.xpi [2012-06-04]
FF Extension: Black Skin - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi [2013-07-04]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-07]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Prezentace Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-12]
CHR Extension: (Dokumenty Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-12]
CHR Extension: (Disk Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-12]
CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-12]
CHR Extension: (Vyhledávání Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-12]
CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-07] (BlueStack Systems, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 lxdi_device; C:\windows\system32\lxdicoms.exe [876976 2007-04-26] ( )
R2 lxdi_device; C:\windows\SysWOW64\lxdicoms.exe [517040 2007-04-26] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-03-10] ()
R2 wgclbhvqtgnwlt; c:\windows\SysWOW64\HUAYNF~1.EXE [102400 2012-04-15] ( Company (R)) [File not signed]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [X]
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [31080 2012-08-30] (AVG Technologies)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-07] (BlueStack Systems)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PcdrNdisuio; C:\Windows\SysWow64\drivers\pcdrndisuio.sys [19456 2009-12-17] (Windows (R) Codename Longhorn DDK provider)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
U3 BcmSqlStartupSvc; No ImagePath
U2 IAStorDataMgrSvc; No ImagePath
U2 IviRegMgr; No ImagePath
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0; \??\f:\pcdoctor\pcdsrvc_x64.pkms [X]
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 11:37 - 2014-11-12 11:39 - 00018844 _____ () C:\Users\Nikola\Desktop\FRST.txt
2014-11-12 11:36 - 2014-11-12 11:36 - 00029696 _____ () C:\Users\Nikola\AppData\Local\MSGBOX.EXE
2014-11-12 11:36 - 2014-11-12 11:36 - 00015327 _____ () C:\Users\Nikola\Desktop\LM.bat
2014-11-12 11:35 - 2014-11-12 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload
2014-11-12 11:33 - 2014-11-12 11:38 - 00000000 ____D () C:\FRST
2014-11-12 11:31 - 2014-11-12 11:32 - 02116096 _____ (Farbar) C:\Users\Nikola\Desktop\FRST64.exe
2014-11-12 10:22 - 2014-11-12 09:46 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-12 10:13 - 2014-11-12 10:30 - 00000000 ____D () C:\zoek
2014-11-12 09:51 - 2014-11-12 10:30 - 00026731 _____ () C:\zoek-results.log
2014-11-12 09:49 - 2014-11-05 19:37 - 01294848 _____ () C:\Users\Nikola\Desktop\zoek.exe
2014-11-12 09:48 - 2014-11-12 09:49 - 00000000 ____D () C:\Users\Nikola\Downloads\zoek
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.scr
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.com
2014-11-12 09:47 - 2014-11-12 09:47 - 04124640 _____ () C:\Users\Nikola\Downloads\zoek.zip
2014-11-12 09:39 - 2014-11-12 10:19 - 00000000 ____D () C:\zoek_backup
2014-11-12 09:18 - 2014-11-12 09:18 - 02140160 _____ () C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
2014-11-12 08:30 - 2014-11-12 08:30 - 00000000 ____D () C:\rsit
2014-11-12 08:20 - 2014-11-12 08:20 - 00000004 _____ () C:\Users\Nikola\AppData\Roaming\appdataFr2.bin
2014-11-10 15:13 - 2014-11-10 17:13 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-11-10 15:13 - 2014-11-10 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-11-05 19:16 - 2014-11-05 19:16 - 01485024 _____ () C:\Users\Nikola\Desktop\Nový WinRAR archiv.rar
2014-11-05 18:52 - 2014-11-05 18:52 - 00559616 _____ () C:\Users\Nikola\Desktop\5006.ppt
2014-11-05 18:52 - 2014-11-05 18:52 - 00342528 _____ () C:\Users\Nikola\Desktop\5049 (1).ppt
2014-11-05 18:51 - 2014-11-05 18:51 - 00342528 _____ () C:\Users\Nikola\Desktop\5049.ppt
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\windows\SysWOW64\CNC_BVL.dll
2014-11-04 21:58 - 2012-11-26 12:32 - 00088576 _____ () C:\windows\SysWOW64\CNC176ED.TBL
2014-11-04 21:58 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\windows\SysWOW64\CNHMCA.dll
2014-11-04 21:56 - 2014-11-04 21:56 - 00000000 ____D () C:\windows\system32\STRING
2014-11-04 21:56 - 2013-01-24 16:24 - 00359936 _____ (CANON INC.) C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:56 - 2013-01-24 16:24 - 00039424 _____ (CANON INC.) C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56 - 2013-01-24 16:23 - 00366592 _____ (CANON INC.) C:\windows\SysWOW64\CNMNPPM.DLL
2014-11-04 21:55 - 2014-11-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3500 series
2014-11-04 21:54 - 2013-04-04 05:00 - 00391168 _____ (CANON INC.) C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51 - 2014-11-04 21:51 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2014-11-04 21:48 - 2014-11-04 21:49 - 50974296 _____ () C:\Users\Nikola\Desktop\win-mg3500-1_0-mcd.exe
2014-11-04 20:14 - 2014-11-04 20:14 - 00796672 _____ () C:\Users\Nikola\Desktop\4993.ppt
2014-11-04 20:13 - 2014-11-04 20:13 - 01345536 _____ () C:\Users\Nikola\Desktop\5498.ppt
2014-11-04 19:50 - 2014-11-04 19:50 - 08658432 _____ () C:\Users\Nikola\Desktop\trávicí soustava.ppt
2014-11-03 21:15 - 2014-11-03 21:16 - 761700688 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-528.-Přesně-podle-plánu.avi
2014-11-03 19:14 - 2014-11-03 19:17 - 623009092 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-527.--Hurá-do-Egypta!-4.11.2014.avi
2014-10-31 23:08 - 2014-10-31 23:08 - 186434536 _____ () C:\Users\Nikola\Desktop\výstava.zip
2014-10-31 23:07 - 2014-10-31 23:07 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka – kopie
2014-10-31 22:58 - 2014-10-31 22:58 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka (2)
2014-10-26 07:10 - 2014-10-26 07:10 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09 - 2014-10-26 07:09 - 00000000 ___HD () C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52 - 2014-10-26 07:42 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-10-26 06:39 - 2014-11-04 22:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-10-26 06:36 - 2014-11-04 22:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-10-25 18:44 - 2014-10-31 23:05 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka
2014-10-17 22:20 - 2014-10-17 22:21 - 08219532 _____ () C:\Users\Nikola\Desktop\5351.ppt
2014-10-17 20:03 - 2014-11-10 21:04 - 00000000 ____D () C:\Users\Nikola\Desktop\septima
2014-10-16 16:25 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-16 16:25 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-16 16:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-16 16:25 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-16 16:25 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-16 16:25 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-16 16:25 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-16 16:25 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-16 16:25 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-16 16:25 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-16 16:25 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-16 16:25 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-16 16:25 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-16 16:25 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-16 16:25 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-16 16:25 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-16 16:25 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-16 16:25 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-16 16:25 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-16 16:23 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-16 16:23 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-10-16 16:23 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-16 16:23 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-16 16:23 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-10-16 16:22 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-16 16:22 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 11:21 - 2012-04-21 19:39 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-11-12 10:55 - 2010-08-25 14:39 - 02012298 _____ () C:\windows\WindowsUpdate.log
2014-11-12 10:43 - 2013-10-13 18:06 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-12 10:31 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 10:31 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 10:30 - 2013-10-13 18:06 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-12 10:23 - 2014-06-04 15:25 - 00004696 _____ () C:\windows\PFRO.log
2014-11-12 10:23 - 2014-05-18 12:27 - 00003756 _____ () C:\windows\setupact.log
2014-11-12 10:23 - 2014-02-02 18:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-12 10:23 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-12 10:19 - 2014-08-26 11:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-11-12 10:16 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-12 09:26 - 2013-09-10 13:19 - 00000000 ____D () C:\AdwCleaner
2014-11-12 08:30 - 2012-10-26 14:19 - 00000000 ____D () C:\Program Files\trend micro
2014-11-11 21:35 - 2012-04-21 19:39 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 21:35 - 2012-04-21 19:39 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 21:35 - 2011-06-09 20:16 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-10 15:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-10 15:14 - 2014-04-20 17:07 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-10 15:04 - 2014-04-20 17:06 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-09 19:53 - 2010-08-25 06:06 - 00682520 _____ () C:\windows\system32\perfh005.dat
2014-11-09 19:53 - 2010-08-25 06:06 - 00145906 _____ () C:\windows\system32\perfc005.dat
2014-11-09 19:53 - 2009-07-14 06:13 - 00860088 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-08 21:15 - 2012-09-29 09:43 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58 - 2009-07-14 04:20 - 00000000 __RSD () C:\windows\Media
2014-11-04 21:55 - 2011-08-13 10:16 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-11-04 21:41 - 2011-11-09 18:04 - 00000000 ____D () C:\ProgramData\Lx_cats
2014-10-31 06:25 - 2011-06-03 19:13 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40 - 2013-08-25 21:10 - 00000000 ____D () C:\filmy
2014-10-30 12:25 - 2011-05-25 22:04 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-10-28 20:30 - 2012-09-25 14:31 - 00000000 ____D () C:\Users\Guest
2014-10-28 20:30 - 2012-09-25 14:16 - 00000000 ____D () C:\Users\Next
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP140 series
2014-10-28 20:30 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-10-28 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration
2014-10-28 19:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-10-25 22:48 - 2014-08-12 20:52 - 00000000 ____D () C:\Users\Nikola\AppData\Local\Adobe
2014-10-18 02:38 - 2011-05-07 19:37 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-18 02:38 - 2011-05-07 19:37 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-18 00:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-10-17 20:18 - 2012-07-12 23:28 - 00000000 ___RD () C:\Users\Nikola\Desktop\Fotky
2014-10-17 20:13 - 2013-03-26 20:01 - 00000000 ____D () C:\Users\Nikola\Desktop\Škola
2014-10-17 18:22 - 2009-07-14 05:45 - 00441880 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-17 18:16 - 2011-05-14 12:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-17 17:39 - 2013-07-25 02:01 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 16:24 - 2011-05-29 20:29 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 20:45
==================== End Of Log ============================
Ran by Nikola (administrator) on NIKOLA-PC on 12-11-2014 11:37:52
Running from C:\Users\Nikola\Desktop
Loaded Profile: Nikola (Available profiles: Nikola & Next & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
( Company (R)) C:\Windows\SysWOW64\HUAYNF~1.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
( ) C:\Windows\System32\lxdicoms.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
(Lexmark) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1894696 2010-01-07] (Synaptics Incorporated)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [lxdimon.exe] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [435120 2007-05-07] ()
HKLM\...\Run: [lxdiamon] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [20480 2007-03-05] (Lexmark)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [FaxCenterServer] => C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [312240 2007-05-07] ()
HKLM-x32\...\Run: [Freecorder FLV Service] => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe"
HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480 2014-10-07] (BlueStack Systems, Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-02]
FF Extension: Seznam lištička - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-28]
FF Extension: Fotofox - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\fotofox@mozilla.com.xpi [2012-06-04]
FF Extension: FREE MP3 Search - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\search@org-com.eu.xpi [2012-06-04]
FF Extension: Black Skin - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi [2013-07-04]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-07]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Prezentace Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-12]
CHR Extension: (Dokumenty Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-12]
CHR Extension: (Disk Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-12]
CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-12]
CHR Extension: (Vyhledávání Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-12]
CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-07] (BlueStack Systems, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 lxdi_device; C:\windows\system32\lxdicoms.exe [876976 2007-04-26] ( )
R2 lxdi_device; C:\windows\SysWOW64\lxdicoms.exe [517040 2007-04-26] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-03-10] ()
R2 wgclbhvqtgnwlt; c:\windows\SysWOW64\HUAYNF~1.EXE [102400 2012-04-15] ( Company (R)) [File not signed]
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [X]
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [31080 2012-08-30] (AVG Technologies)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-07] (BlueStack Systems)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PcdrNdisuio; C:\Windows\SysWow64\drivers\pcdrndisuio.sys [19456 2009-12-17] (Windows (R) Codename Longhorn DDK provider)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
U3 BcmSqlStartupSvc; No ImagePath
U2 IAStorDataMgrSvc; No ImagePath
U2 IviRegMgr; No ImagePath
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0; \??\f:\pcdoctor\pcdsrvc_x64.pkms [X]
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 11:37 - 2014-11-12 11:39 - 00018844 _____ () C:\Users\Nikola\Desktop\FRST.txt
2014-11-12 11:36 - 2014-11-12 11:36 - 00029696 _____ () C:\Users\Nikola\AppData\Local\MSGBOX.EXE
2014-11-12 11:36 - 2014-11-12 11:36 - 00015327 _____ () C:\Users\Nikola\Desktop\LM.bat
2014-11-12 11:35 - 2014-11-12 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload
2014-11-12 11:33 - 2014-11-12 11:38 - 00000000 ____D () C:\FRST
2014-11-12 11:31 - 2014-11-12 11:32 - 02116096 _____ (Farbar) C:\Users\Nikola\Desktop\FRST64.exe
2014-11-12 10:22 - 2014-11-12 09:46 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-12 10:13 - 2014-11-12 10:30 - 00000000 ____D () C:\zoek
2014-11-12 09:51 - 2014-11-12 10:30 - 00026731 _____ () C:\zoek-results.log
2014-11-12 09:49 - 2014-11-05 19:37 - 01294848 _____ () C:\Users\Nikola\Desktop\zoek.exe
2014-11-12 09:48 - 2014-11-12 09:49 - 00000000 ____D () C:\Users\Nikola\Downloads\zoek
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.scr
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.com
2014-11-12 09:47 - 2014-11-12 09:47 - 04124640 _____ () C:\Users\Nikola\Downloads\zoek.zip
2014-11-12 09:39 - 2014-11-12 10:19 - 00000000 ____D () C:\zoek_backup
2014-11-12 09:18 - 2014-11-12 09:18 - 02140160 _____ () C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
2014-11-12 08:30 - 2014-11-12 08:30 - 00000000 ____D () C:\rsit
2014-11-12 08:20 - 2014-11-12 08:20 - 00000004 _____ () C:\Users\Nikola\AppData\Roaming\appdataFr2.bin
2014-11-10 15:13 - 2014-11-10 17:13 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-11-10 15:13 - 2014-11-10 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-11-05 19:16 - 2014-11-05 19:16 - 01485024 _____ () C:\Users\Nikola\Desktop\Nový WinRAR archiv.rar
2014-11-05 18:52 - 2014-11-05 18:52 - 00559616 _____ () C:\Users\Nikola\Desktop\5006.ppt
2014-11-05 18:52 - 2014-11-05 18:52 - 00342528 _____ () C:\Users\Nikola\Desktop\5049 (1).ppt
2014-11-05 18:51 - 2014-11-05 18:51 - 00342528 _____ () C:\Users\Nikola\Desktop\5049.ppt
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\windows\SysWOW64\CNC_BVL.dll
2014-11-04 21:58 - 2012-11-26 12:32 - 00088576 _____ () C:\windows\SysWOW64\CNC176ED.TBL
2014-11-04 21:58 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\windows\SysWOW64\CNHMCA.dll
2014-11-04 21:56 - 2014-11-04 21:56 - 00000000 ____D () C:\windows\system32\STRING
2014-11-04 21:56 - 2013-01-24 16:24 - 00359936 _____ (CANON INC.) C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:56 - 2013-01-24 16:24 - 00039424 _____ (CANON INC.) C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56 - 2013-01-24 16:23 - 00366592 _____ (CANON INC.) C:\windows\SysWOW64\CNMNPPM.DLL
2014-11-04 21:55 - 2014-11-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3500 series
2014-11-04 21:54 - 2013-04-04 05:00 - 00391168 _____ (CANON INC.) C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51 - 2014-11-04 21:51 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2014-11-04 21:48 - 2014-11-04 21:49 - 50974296 _____ () C:\Users\Nikola\Desktop\win-mg3500-1_0-mcd.exe
2014-11-04 20:14 - 2014-11-04 20:14 - 00796672 _____ () C:\Users\Nikola\Desktop\4993.ppt
2014-11-04 20:13 - 2014-11-04 20:13 - 01345536 _____ () C:\Users\Nikola\Desktop\5498.ppt
2014-11-04 19:50 - 2014-11-04 19:50 - 08658432 _____ () C:\Users\Nikola\Desktop\trávicí soustava.ppt
2014-11-03 21:15 - 2014-11-03 21:16 - 761700688 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-528.-Přesně-podle-plánu.avi
2014-11-03 19:14 - 2014-11-03 19:17 - 623009092 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-527.--Hurá-do-Egypta!-4.11.2014.avi
2014-10-31 23:08 - 2014-10-31 23:08 - 186434536 _____ () C:\Users\Nikola\Desktop\výstava.zip
2014-10-31 23:07 - 2014-10-31 23:07 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka – kopie
2014-10-31 22:58 - 2014-10-31 22:58 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka (2)
2014-10-26 07:10 - 2014-10-26 07:10 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09 - 2014-10-26 07:09 - 00000000 ___HD () C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52 - 2014-10-26 07:42 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-10-26 06:39 - 2014-11-04 22:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-10-26 06:36 - 2014-11-04 22:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-10-25 18:44 - 2014-10-31 23:05 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka
2014-10-17 22:20 - 2014-10-17 22:21 - 08219532 _____ () C:\Users\Nikola\Desktop\5351.ppt
2014-10-17 20:03 - 2014-11-10 21:04 - 00000000 ____D () C:\Users\Nikola\Desktop\septima
2014-10-16 16:25 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-16 16:25 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-16 16:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-16 16:25 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-16 16:25 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-16 16:25 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-16 16:25 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-16 16:25 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-16 16:25 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-16 16:25 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-16 16:25 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-16 16:25 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-16 16:25 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-16 16:25 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-16 16:25 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-16 16:25 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-16 16:25 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-16 16:25 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-16 16:25 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-16 16:23 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-16 16:23 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-10-16 16:23 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-16 16:23 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-16 16:23 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-10-16 16:22 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-16 16:22 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 11:21 - 2012-04-21 19:39 - 00000914 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-11-12 10:55 - 2010-08-25 14:39 - 02012298 _____ () C:\windows\WindowsUpdate.log
2014-11-12 10:43 - 2013-10-13 18:06 - 00000952 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-12 10:31 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 10:31 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 10:30 - 2013-10-13 18:06 - 00000948 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-12 10:23 - 2014-06-04 15:25 - 00004696 _____ () C:\windows\PFRO.log
2014-11-12 10:23 - 2014-05-18 12:27 - 00003756 _____ () C:\windows\setupact.log
2014-11-12 10:23 - 2014-02-02 18:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-12 10:23 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-12 10:19 - 2014-08-26 11:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-11-12 10:16 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-12 09:26 - 2013-09-10 13:19 - 00000000 ____D () C:\AdwCleaner
2014-11-12 08:30 - 2012-10-26 14:19 - 00000000 ____D () C:\Program Files\trend micro
2014-11-11 21:35 - 2012-04-21 19:39 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 21:35 - 2012-04-21 19:39 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 21:35 - 2011-06-09 20:16 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-10 15:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-10 15:14 - 2014-04-20 17:07 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-10 15:04 - 2014-04-20 17:06 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-09 19:53 - 2010-08-25 06:06 - 00682520 _____ () C:\windows\system32\perfh005.dat
2014-11-09 19:53 - 2010-08-25 06:06 - 00145906 _____ () C:\windows\system32\perfc005.dat
2014-11-09 19:53 - 2009-07-14 06:13 - 00860088 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-08 21:15 - 2012-09-29 09:43 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58 - 2009-07-14 04:20 - 00000000 __RSD () C:\windows\Media
2014-11-04 21:55 - 2011-08-13 10:16 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-11-04 21:41 - 2011-11-09 18:04 - 00000000 ____D () C:\ProgramData\Lx_cats
2014-10-31 06:25 - 2011-06-03 19:13 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40 - 2013-08-25 21:10 - 00000000 ____D () C:\filmy
2014-10-30 12:25 - 2011-05-25 22:04 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-10-28 20:30 - 2012-09-25 14:31 - 00000000 ____D () C:\Users\Guest
2014-10-28 20:30 - 2012-09-25 14:16 - 00000000 ____D () C:\Users\Next
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP140 series
2014-10-28 20:30 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-10-28 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration
2014-10-28 19:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-10-25 22:48 - 2014-08-12 20:52 - 00000000 ____D () C:\Users\Nikola\AppData\Local\Adobe
2014-10-18 02:38 - 2011-05-07 19:37 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-18 02:38 - 2011-05-07 19:37 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-18 00:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-10-17 20:18 - 2012-07-12 23:28 - 00000000 ___RD () C:\Users\Nikola\Desktop\Fotky
2014-10-17 20:13 - 2013-03-26 20:01 - 00000000 ____D () C:\Users\Nikola\Desktop\Škola
2014-10-17 18:22 - 2009-07-14 05:45 - 00441880 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-17 18:16 - 2011-05-14 12:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-17 17:39 - 2013-07-25 02:01 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 16:24 - 2011-05-29 20:29 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 20:45
==================== End Of Log ============================
- Přílohy
-
- Addition.rar
- (10.26 KiB) Staženo 77 x
Re: Zavirovaný ntb


- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - DefaultScope value is missing. FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-07] FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found] FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found] CHR dev: Chrome dev build detected! <======= ATTENTION S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [X] C:\Program Files (x86)\McAfee Security Scan U3 BcmSqlStartupSvc; No ImagePath U2 IAStorDataMgrSvc; No ImagePath U2 IviRegMgr; No ImagePath U2 RichVideo; No ImagePath U3 SQLWriter; No ImagePath 2014-11-12 11:36 - 2014-11-12 11:36 - 00029696 _____ () C:\Users\Nikola\AppData\Local\MSGBOX.EXE 2014-11-12 11:36 - 2014-11-12 11:36 - 00015327 _____ () C:\Users\Nikola\Desktop\LM.bat 2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload 2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload 2014-11-12 10:22 - 2014-11-12 09:46 - 00024064 _____ () C:\windows\zoek-delete.exe 2014-11-12 10:13 - 2014-11-12 10:30 - 00000000 ____D () C:\zoek 2014-11-12 09:51 - 2014-11-12 10:30 - 00026731 _____ () C:\zoek-results.log 2014-11-12 09:49 - 2014-11-05 19:37 - 01294848 _____ () C:\Users\Nikola\Desktop\zoek.exe 2014-11-12 09:48 - 2014-11-12 09:49 - 00000000 ____D () C:\Users\Nikola\Downloads\zoek 2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.scr 2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.com 2014-11-12 09:47 - 2014-11-12 09:47 - 04124640 _____ () C:\Users\Nikola\Downloads\zoek.zip 2014-11-12 09:39 - 2014-11-12 10:19 - 00000000 ____D () C:\zoek_backup Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe AlternateDataStreams: C:\ProgramData\Temp:373E1720 AlternateDataStreams: C:\ProgramData\Temp:8927A071 Hosts: EmptyTemp: End

Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
Edit: chrome vypada v poradku
total virus nasel:
AVware Trojan-Spy.Win32.Keylogger.fq (v) 20141112
Comodo TrojWare.Win32.Spy.KeyLogger.ODI 20141112
Malwarebytes Trojan.KeyLogger 20141112
Norman KeyLogger.DLE 20141112
VIPRE Trojan-Spy.Win32.Keylogger.fq (v) 20141112
Fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-11-2014
Ran by Nikola at 2014-11-12 12:05:54 Run:1
Running from C:\Users\Nikola\Desktop
Loaded Profile: Nikola (Available profiles: Nikola & Next & Guest)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-07]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
CHR dev: Chrome dev build detected! <======= ATTENTION
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [X]
C:\Program Files (x86)\McAfee Security Scan
U3 BcmSqlStartupSvc; No ImagePath
U2 IAStorDataMgrSvc; No ImagePath
U2 IviRegMgr; No ImagePath
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
2014-11-12 11:36 - 2014-11-12 11:36 - 00029696 _____ () C:\Users\Nikola\AppData\Local\MSGBOX.EXE
2014-11-12 11:36 - 2014-11-12 11:36 - 00015327 _____ () C:\Users\Nikola\Desktop\LM.bat
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload
2014-11-12 10:22 - 2014-11-12 09:46 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-12 10:13 - 2014-11-12 10:30 - 00000000 ____D () C:\zoek
2014-11-12 09:51 - 2014-11-12 10:30 - 00026731 _____ () C:\zoek-results.log
2014-11-12 09:49 - 2014-11-05 19:37 - 01294848 _____ () C:\Users\Nikola\Desktop\zoek.exe
2014-11-12 09:48 - 2014-11-12 09:49 - 00000000 ____D () C:\Users\Nikola\Downloads\zoek
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.scr
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.com
2014-11-12 09:47 - 2014-11-12 09:47 - 04124640 _____ () C:\Users\Nikola\Downloads\zoek.zip
2014-11-12 09:39 - 2014-11-12 10:19 - 00000000 ____D () C:\zoek_backup
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:8927A071
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GShortCut => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ROC_roc_ssl_v12 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
"HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-2772758291-4078256221-3500050187-1001" => Key not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key Deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff not found.
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com not found.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
McComponentHostService => Service deleted successfully.
"C:\Program Files (x86)\McAfee Security Scan" => File/Directory not found.
BcmSqlStartupSvc => Service deleted successfully.
IAStorDataMgrSvc => Service deleted successfully.
IviRegMgr => Service deleted successfully.
RichVideo => Service deleted successfully.
SQLWriter => Service deleted successfully.
C:\Users\Nikola\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Nikola\Desktop\LM.bat => Moved successfully.
C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload => Moved successfully.
C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload => Moved successfully.
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Nikola\Desktop\zoek.exe => Moved successfully.
C:\Users\Nikola\Downloads\zoek => Moved successfully.
C:\Users\Nikola\Desktop\zoek.scr => Moved successfully.
C:\Users\Nikola\Desktop\zoek.com => Moved successfully.
C:\Users\Nikola\Downloads\zoek.zip => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\Temp => ":373E1720" ADS removed successfully.
C:\ProgramData\Temp => ":8927A071" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 72.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
total virus nasel:
AVware Trojan-Spy.Win32.Keylogger.fq (v) 20141112
Comodo TrojWare.Win32.Spy.KeyLogger.ODI 20141112
Malwarebytes Trojan.KeyLogger 20141112
Norman KeyLogger.DLE 20141112
VIPRE Trojan-Spy.Win32.Keylogger.fq (v) 20141112
Fixlog:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-11-2014
Ran by Nikola at 2014-11-12 12:05:54 Run:1
Running from C:\Users\Nikola\Desktop
Loaded Profile: Nikola (Available profiles: Nikola & Next & Guest)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ROC_roc_ssl_v12] => "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-04-07]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
CHR dev: Chrome dev build detected! <======= ATTENTION
S3 McComponentHostService; "C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe" [X]
C:\Program Files (x86)\McAfee Security Scan
U3 BcmSqlStartupSvc; No ImagePath
U2 IAStorDataMgrSvc; No ImagePath
U2 IviRegMgr; No ImagePath
U2 RichVideo; No ImagePath
U3 SQLWriter; No ImagePath
2014-11-12 11:36 - 2014-11-12 11:36 - 00029696 _____ () C:\Users\Nikola\AppData\Local\MSGBOX.EXE
2014-11-12 11:36 - 2014-11-12 11:36 - 00015327 _____ () C:\Users\Nikola\Desktop\LM.bat
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload
2014-11-12 11:34 - 2014-11-12 11:34 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload
2014-11-12 10:22 - 2014-11-12 09:46 - 00024064 _____ () C:\windows\zoek-delete.exe
2014-11-12 10:13 - 2014-11-12 10:30 - 00000000 ____D () C:\zoek
2014-11-12 09:51 - 2014-11-12 10:30 - 00026731 _____ () C:\zoek-results.log
2014-11-12 09:49 - 2014-11-05 19:37 - 01294848 _____ () C:\Users\Nikola\Desktop\zoek.exe
2014-11-12 09:48 - 2014-11-12 09:49 - 00000000 ____D () C:\Users\Nikola\Downloads\zoek
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.scr
2014-11-12 09:48 - 2014-10-29 11:01 - 01424929 _____ () C:\Users\Nikola\Desktop\zoek.com
2014-11-12 09:47 - 2014-11-12 09:47 - 04124640 _____ () C:\Users\Nikola\Downloads\zoek.zip
2014-11-12 09:39 - 2014-11-12 10:19 - 00000000 ____D () C:\zoek_backup
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\Temp:373E1720
AlternateDataStreams: C:\ProgramData\Temp:8927A071
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdateP2GShortCut => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\GrooveMonitor => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ROC_roc_ssl_v12 => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
"HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\S-1-5-21-2772758291-4078256221-3500050187-1001" => Key not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\URLSearchHooks\\ => value deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key deleted successfully.
"HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@mcafee.com/McAfeeMssPlugin" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key Deleted successfully.
C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} => Moved successfully.
C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff not found.
C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com not found.
CHR dev: Chrome dev build detected! <======= ATTENTION => Error: No automatic fix found for this entry.
McComponentHostService => Service deleted successfully.
"C:\Program Files (x86)\McAfee Security Scan" => File/Directory not found.
BcmSqlStartupSvc => Service deleted successfully.
IAStorDataMgrSvc => Service deleted successfully.
IviRegMgr => Service deleted successfully.
RichVideo => Service deleted successfully.
SQLWriter => Service deleted successfully.
C:\Users\Nikola\AppData\Local\MSGBOX.EXE => Moved successfully.
C:\Users\Nikola\Desktop\LM.bat => Moved successfully.
C:\Users\Nikola\Downloads\Nepotvrzeno 709912.crdownload => Moved successfully.
C:\Users\Nikola\Downloads\Nepotvrzeno 24876.crdownload => Moved successfully.
C:\windows\zoek-delete.exe => Moved successfully.
C:\zoek => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\Users\Nikola\Desktop\zoek.exe => Moved successfully.
C:\Users\Nikola\Downloads\zoek => Moved successfully.
C:\Users\Nikola\Desktop\zoek.scr => Moved successfully.
C:\Users\Nikola\Desktop\zoek.com => Moved successfully.
C:\Users\Nikola\Downloads\zoek.zip => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\ProgramData\Temp => ":373E1720" ADS removed successfully.
C:\ProgramData\Temp => ":8927A071" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 72.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Zavirovaný ntb




Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
po 3 hodinách hotovo 
jen jsem do prilohy hodil screen ze to naslo nejake skodlive polozky a v logu to neni zahrnuto (?)
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Datum skenování: 12.11.2014
Čas skenování: 12:23:25
Protokol: malwlog.txt
Správce: Ano
Verze: 2.00.3.1025
Databáze malwaru: v2014.11.12.06
Databáze rootkitů: v2014.11.11.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Nikola
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 601852
Uplynulý čas: 3 hod, 11 min, 28 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 14
Trojan.KeyLogger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wgclbhvqtgnwlt, , [faecc476a9d343f3c692e723f8098f71],
PUP.Optional.MediaBuzz.A, HKLM\SOFTWARE\WOW6432NODE\MediaBuzzV1mode4070, , [d80ee2584834e55109673e1b9d66e11f],
PUP.Optional.MediaPlayerAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerV1alpha5009, , [02e458e2a8d476c01d565c0eee1504fc],
PUP.Optional.MediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewerV1alpha1655, , [11d5d763de9eca6c83689fc6b44f748c],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha3743, , [fbeb6dcd4f2de452d86be283a45f13ed],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha6152, , [4b9b65d5304c1323f2511550c73c6d93],
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MediaWatchV1home427, , [a34321194537e05698c41c81937129d7],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release2297, , [e50178c2a0dcfd39d2d200532cd717e9],
PUP.Optional.ShopUp.A, HKLM\SOFTWARE\WOW6432NODE\Shopp_Upe_1.8-nv, , [4f9736044f2d5adc25b8b383cb3818e8],
PUP.Optional.ShopUp.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Shopp_Upe_1.8, , [479f3efcceaedd59a43747ef0bf825db],
PUP.Optional.MoviesToolbar.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\koyotesofttoolbarnew, , [db0b0832304c65d12c6da98c48bbb749],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [c1251822ee8e34029f0a2c3b778c728e],
PUP.Optional.Spigot.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Search Settings, , [d2143208f98358de6eee8d16c53f57a9],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [3ea86ad0bdbfbf77585131362ed56799],
Hodnoty registru: 2
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{F3FEE66E-E034-436a-86E4-9690573BEE8A}, , [4a9c7bbf9be165d1dc272395e81a3dc3],
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{F3FEE66E-E034-436A-86E4-9690573BEE8A}, , [4a9c7bbf9be165d1dc272395e81a3dc3],
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 39
Trojan.KeyLogger, C:\Windows\SysWOW64\huaynfbvh.exe, , [faecc476a9d343f3c692e723f8098f71],
PUP.Optional.Nova.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\7Go Games\66276ad2-cf00-4b69-9507-700bfb55d829.dll.vir, , [5e886fcb6418bf77a7b6865b4cb5c63a],
PUP.Optional.BestToolBars.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\7Go Games\ScriptHost64.dll.vir, , [45a1073317656cca5f6c365b08f99967],
PUP.Optional.OptimizerPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\optimizer pro\OptProSchedule.exe.vir, , [e00679c12755280efce49ba5d32e40c0],
PUP.Optional.OptimizerPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\optimizer pro\OptProSmartScan.exe.vir, , [f0f6e852bcc0d6602db497a97b863ac6],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7.exe.vir, , [677fbf7b1d5fa88e4aab49966899d62a],
PUP.Optional.Nova.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\47711e1f-82b2-472e-939c-7af750d92c7d.dll.vir, , [36b056e45f1dfc3a8bd2cb16956c12ee],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11.exe.vir, , [faecf3475d1ffe38d22316c911f0837d],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2.exe.vir, , [7a6c0436007c2f0724d136a9cd34f20e],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4.exe.vir, , [ecfaa3972359d462ad4839a6629f27d9],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5.exe.vir, , [747258e294e80432c530d50a15ec27d9],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.exe.vir, , [bb2ba49697e557df31c45a85659c2bd5],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-64.exe.vir, , [74727bbf3448a3935f96d80703fef40c],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bg.exe.vir, , [d016dd5d1d5ffe380aeb6a7543bead53],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll.vir, , [aa3c80badd9f1620f20318c702ffca36],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho64.dll.vir, , [668001395527cd697e77db04ba476e92],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-codedownloader.exe.vir, , [ebfb7ebc2953ab8b4ca9f2edfa0708f8],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\utils.exe.vir, , [2eb8b08a44382e087a95e673ba464bb5],
PUP.Optional.7Go.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Speed Analysis 3\uninst.exe.vir, , [02e4a496a6d6201666b0a391bb46946c],
PUP.Optional.MultiPlug, C:\AdwCleaner\Quarantine\C\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll.vir, , [b4323406a5d7cb6b1c67932be41dfa06],
Adware.InstallBrain, C:\AdwCleaner\Quarantine\C\ProgramData\IBUpdaterService\ibsvc.exe.vir, , [d21495a5314b1125a846640eca372fd1],
PUP.Optional.Somoto.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir, , [15d186b467156dc911ea33f0fe03ef11],
PUP.Optional.FilesFrog.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\FilesFrog Update Checker\update_checker.exe.vir, , [6284dc5e2a52c86eea5f5fc4d12fdf21],
PUP.Optional.NextLive.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\genienext\nengine.dll.vir, , [a34379c163196ccad296e18cf50c9a66],
PUP.Optional.Ilivid, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\Ilivid\Uninstall.exe.vir, , [3da99e9c433996a0e40ed110cd34f808],
PUP.Optional.Amonetize, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\SwvUpdater\Updater.exe.vir, , [8e588cae027ac274c6ffd36b6b96c43c],
PUP.Optional.FileScout.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Roaming\file scout\filescout.exe.vir, , [ffe79c9eb4c8c3738046d24e3fc25fa1],
PUP.Optional.NextLive.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Roaming\newnext.me\nengine.dll.vir, , [a244fc3e0b71f93d83e581ecfb06a35d],
PUP.Optional.PCPerformer.A, C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir, , [0cda5bdf4834f046ca45e839f010a45c],
Trojan.Ardamax, C:\ProgramData\VRL\VRL.01, , [9f4782b83745ec4ade0ea74241c37d83],
PUP.Ardamax, C:\ProgramData\VRL\VRL.02, , [cd1916241d5f3006d2916bb71be63bc5],
PUP.Optional.Spigot.A, C:\ProgramData\YTD YouTube Downloader & Converter\ytd_installer.exe, , [925460da5a22ad89694fe73f4eb2b947],
PUP.Optional.Somoto.A, C:\Users\Nikola\AppData\Local\Application Data\Bundled software uninstaller\biclient.exe, , [91555ae09ae22115b40b4ae6fb0618e8],
PUP.Optional.Spigot.A, C:\Users\Nikola\Desktop\A kola\roÄ?nAkovA! prA!ce\Hudba\Niky\Programy\YTDSetup.exe, , [19cdc476e993f0462f899d89de22e51b],
PUP.Optional.Somoto.A, C:\Users\Nikola\Downloads\7ZipSetup.exe, , [de0813274b314de9112dc67250b0fd03],
PUP.Optional.Bandoo, C:\FRST\Quarantine\C\zoek_backup\C_Users_Nikola_Downloads_iLividSetup-r834-n-bc.exe.vir, , [4d9924161369e056920d35ed79886898],
PUP.Optional.Nova.A, C:\FRST\Quarantine\C\zoek_backup\C_PROGRA~2_b2c1a4d4-496e-421e-bdd6-d933c230e3fb\611c7746-ba6c-4837-bab5-e689597e0886.dll, , [a83e3efc275551e56feeaf32d22fe818],
PUP.Optional.Amonetize, C:\FRST\Quarantine\C\zoek_backup\C_Users_Nikola_AppData_Local_2678\a31796.exe, , [e600ce6cb3c942f469b9527ad42d55ab],
PUP.Optional.Searchqu.A, C:\Users\Nikola\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}, , [1ccab585b0cced495c738af97490bd43],
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)

jen jsem do prilohy hodil screen ze to naslo nejake skodlive polozky a v logu to neni zahrnuto (?)
Malwarebytes Anti-Malware
http://www.malwarebytes.org
Datum skenování: 12.11.2014
Čas skenování: 12:23:25
Protokol: malwlog.txt
Správce: Ano
Verze: 2.00.3.1025
Databáze malwaru: v2014.11.12.06
Databáze rootkitů: v2014.11.11.01
Licence: Bezplatná verze
Ochrana proti malwaru: Vypnuto
Ochrana proti škodlivým webovým stránkám: Vypnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Nikola
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 601852
Uplynulý čas: 3 hod, 11 min, 28 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 14
Trojan.KeyLogger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wgclbhvqtgnwlt, , [faecc476a9d343f3c692e723f8098f71],
PUP.Optional.MediaBuzz.A, HKLM\SOFTWARE\WOW6432NODE\MediaBuzzV1mode4070, , [d80ee2584834e55109673e1b9d66e11f],
PUP.Optional.MediaPlayerAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerV1alpha5009, , [02e458e2a8d476c01d565c0eee1504fc],
PUP.Optional.MediaViewer.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewerV1alpha1655, , [11d5d763de9eca6c83689fc6b44f748c],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha3743, , [fbeb6dcd4f2de452d86be283a45f13ed],
PUP.Optional.MediaView.A, HKLM\SOFTWARE\WOW6432NODE\MediaViewV1alpha6152, , [4b9b65d5304c1323f2511550c73c6d93],
PUP.Optional.MediaWatch.A, HKLM\SOFTWARE\WOW6432NODE\MediaWatchV1home427, , [a34321194537e05698c41c81937129d7],
PUP.Optional.RichMediaView.A, HKLM\SOFTWARE\WOW6432NODE\RichMediaViewV1release2297, , [e50178c2a0dcfd39d2d200532cd717e9],
PUP.Optional.ShopUp.A, HKLM\SOFTWARE\WOW6432NODE\Shopp_Upe_1.8-nv, , [4f9736044f2d5adc25b8b383cb3818e8],
PUP.Optional.ShopUp.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Shopp_Upe_1.8, , [479f3efcceaedd59a43747ef0bf825db],
PUP.Optional.MoviesToolbar.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\koyotesofttoolbarnew, , [db0b0832304c65d12c6da98c48bbb749],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [c1251822ee8e34029f0a2c3b778c728e],
PUP.Optional.Spigot.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Search Settings, , [d2143208f98358de6eee8d16c53f57a9],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-2772758291-4078256221-3500050187-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [3ea86ad0bdbfbf77585131362ed56799],
Hodnoty registru: 2
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{F3FEE66E-E034-436a-86E4-9690573BEE8A}, , [4a9c7bbf9be165d1dc272395e81a3dc3],
PUP.Optional.YTDToolbar, HKU\S-1-5-21-2772758291-4078256221-3500050187-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{F3FEE66E-E034-436A-86E4-9690573BEE8A}, , [4a9c7bbf9be165d1dc272395e81a3dc3],
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 39
Trojan.KeyLogger, C:\Windows\SysWOW64\huaynfbvh.exe, , [faecc476a9d343f3c692e723f8098f71],
PUP.Optional.Nova.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\7Go Games\66276ad2-cf00-4b69-9507-700bfb55d829.dll.vir, , [5e886fcb6418bf77a7b6865b4cb5c63a],
PUP.Optional.BestToolBars.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\7Go Games\ScriptHost64.dll.vir, , [45a1073317656cca5f6c365b08f99967],
PUP.Optional.OptimizerPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\optimizer pro\OptProSchedule.exe.vir, , [e00679c12755280efce49ba5d32e40c0],
PUP.Optional.OptimizerPro, C:\AdwCleaner\Quarantine\C\Program Files (x86)\optimizer pro\OptProSmartScan.exe.vir, , [f0f6e852bcc0d6602db497a97b863ac6],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-7.exe.vir, , [677fbf7b1d5fa88e4aab49966899d62a],
PUP.Optional.Nova.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\47711e1f-82b2-472e-939c-7af750d92c7d.dll.vir, , [36b056e45f1dfc3a8bd2cb16956c12ee],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-11.exe.vir, , [faecf3475d1ffe38d22316c911f0837d],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-2.exe.vir, , [7a6c0436007c2f0724d136a9cd34f20e],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-4.exe.vir, , [ecfaa3972359d462ad4839a6629f27d9],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-5.exe.vir, , [747258e294e80432c530d50a15ec27d9],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-6.exe.vir, , [bb2ba49697e557df31c45a85659c2bd5],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\7c68aaf5-ee9a-4cda-b69e-d7cc9ad3e8c1-64.exe.vir, , [74727bbf3448a3935f96d80703fef40c],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bg.exe.vir, , [d016dd5d1d5ffe380aeb6a7543bead53],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho.dll.vir, , [aa3c80badd9f1620f20318c702ffca36],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-bho64.dll.vir, , [668001395527cd697e77db04ba476e92],
PUP.Optional.ShopUp.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\Shopp_Upe_1.8-codedownloader.exe.vir, , [ebfb7ebc2953ab8b4ca9f2edfa0708f8],
PUP.Optional.CrossRider.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Shopp_Upe_1.8\utils.exe.vir, , [2eb8b08a44382e087a95e673ba464bb5],
PUP.Optional.7Go.A, C:\AdwCleaner\Quarantine\C\Program Files (x86)\Speed Analysis 3\uninst.exe.vir, , [02e4a496a6d6201666b0a391bb46946c],
PUP.Optional.MultiPlug, C:\AdwCleaner\Quarantine\C\ProgramData\CoolSaleCoupon\ioFrpXNcCAXZBU.dll.vir, , [b4323406a5d7cb6b1c67932be41dfa06],
Adware.InstallBrain, C:\AdwCleaner\Quarantine\C\ProgramData\IBUpdaterService\ibsvc.exe.vir, , [d21495a5314b1125a846640eca372fd1],
PUP.Optional.Somoto.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir, , [15d186b467156dc911ea33f0fe03ef11],
PUP.Optional.FilesFrog.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\FilesFrog Update Checker\update_checker.exe.vir, , [6284dc5e2a52c86eea5f5fc4d12fdf21],
PUP.Optional.NextLive.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\genienext\nengine.dll.vir, , [a34379c163196ccad296e18cf50c9a66],
PUP.Optional.Ilivid, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\Ilivid\Uninstall.exe.vir, , [3da99e9c433996a0e40ed110cd34f808],
PUP.Optional.Amonetize, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Local\SwvUpdater\Updater.exe.vir, , [8e588cae027ac274c6ffd36b6b96c43c],
PUP.Optional.FileScout.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Roaming\file scout\filescout.exe.vir, , [ffe79c9eb4c8c3738046d24e3fc25fa1],
PUP.Optional.NextLive.A, C:\AdwCleaner\Quarantine\C\Users\Nikola\AppData\Roaming\newnext.me\nengine.dll.vir, , [a244fc3e0b71f93d83e581ecfb06a35d],
PUP.Optional.PCPerformer.A, C:\AdwCleaner\Quarantine\C\windows\System32\roboot64.exe.vir, , [0cda5bdf4834f046ca45e839f010a45c],
Trojan.Ardamax, C:\ProgramData\VRL\VRL.01, , [9f4782b83745ec4ade0ea74241c37d83],
PUP.Ardamax, C:\ProgramData\VRL\VRL.02, , [cd1916241d5f3006d2916bb71be63bc5],
PUP.Optional.Spigot.A, C:\ProgramData\YTD YouTube Downloader & Converter\ytd_installer.exe, , [925460da5a22ad89694fe73f4eb2b947],
PUP.Optional.Somoto.A, C:\Users\Nikola\AppData\Local\Application Data\Bundled software uninstaller\biclient.exe, , [91555ae09ae22115b40b4ae6fb0618e8],
PUP.Optional.Spigot.A, C:\Users\Nikola\Desktop\A kola\roÄ?nAkovA! prA!ce\Hudba\Niky\Programy\YTDSetup.exe, , [19cdc476e993f0462f899d89de22e51b],
PUP.Optional.Somoto.A, C:\Users\Nikola\Downloads\7ZipSetup.exe, , [de0813274b314de9112dc67250b0fd03],
PUP.Optional.Bandoo, C:\FRST\Quarantine\C\zoek_backup\C_Users_Nikola_Downloads_iLividSetup-r834-n-bc.exe.vir, , [4d9924161369e056920d35ed79886898],
PUP.Optional.Nova.A, C:\FRST\Quarantine\C\zoek_backup\C_PROGRA~2_b2c1a4d4-496e-421e-bdd6-d933c230e3fb\611c7746-ba6c-4837-bab5-e689597e0886.dll, , [a83e3efc275551e56feeaf32d22fe818],
PUP.Optional.Amonetize, C:\FRST\Quarantine\C\zoek_backup\C_Users_Nikola_AppData_Local_2678\a31796.exe, , [e600ce6cb3c942f469b9527ad42d55ab],
PUP.Optional.Searchqu.A, C:\Users\Nikola\AppData\Roaming\Mozilla\Extensions\{1FD91A9C-410C-4090-BBCC-55D3450EF433}, , [1ccab585b0cced495c738af97490bd43],
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
- Přílohy
-
- screen.rar
- (63.42 KiB) Staženo 84 x
Re: Zavirovaný ntb

Kód: Vybrat vše
Trojan.KeyLogger, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wgclbhvqtgnwlt, , [faecc476a9d343f3c692e723f8098f71],
Trojan.KeyLogger, C:\Windows\SysWOW64\huaynfbvh.exe, , [faecc476a9d343f3c692e723f8098f71],
Trojan.Ardamax, C:\ProgramData\VRL\VRL.01, , [9f4782b83745ec4ade0ea74241c37d83],
PUP.Ardamax, C:\ProgramData\VRL\VRL.02, , [cd1916241d5f3006d2916bb71be63bc5],
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
urcite mazeme
Re: Zavirovaný ntb


Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: Zavirovaný ntb
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-11-2014
Ran by Nikola (administrator) on NIKOLA-PC on 12-11-2014 16:00:41
Running from C:\Users\Nikola\Desktop
Loaded Profiles: Nikola & Next & Guest (Available profiles: Nikola & Next & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
( Company (R)) C:\Windows\SysWOW64\HUAYNF~1.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
( ) C:\Windows\System32\lxdicoms.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
(Lexmark) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1894696 2010-01-07] (Synaptics Incorporated)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [lxdimon.exe] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [435120 2007-05-07] ()
HKLM\...\Run: [lxdiamon] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [20480 2007-03-05] (Lexmark)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\...\Run: [FaxCenterServer] => C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [312240 2007-05-07] ()
HKLM-x32\...\Run: [Freecorder FLV Service] => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe"
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480 2014-10-07] (BlueStack Systems, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-10-01] (Malwarebytes Corporation)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-2772758291-4078256221-3500050187-1005\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-501\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-02]
FF Extension: Seznam lištička - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-28]
FF Extension: Fotofox - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\fotofox@mozilla.com.xpi [2012-06-04]
FF Extension: FREE MP3 Search - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\search@org-com.eu.xpi [2012-06-04]
FF Extension: Black Skin - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi [2013-07-04]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Prezentace Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-12]
CHR Extension: (Dokumenty Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-12]
CHR Extension: (Disk Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-12]
CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-12]
CHR Extension: (Vyhledávání Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-12]
CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-07] (BlueStack Systems, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 lxdi_device; C:\windows\system32\lxdicoms.exe [876976 2007-04-26] ( )
R2 lxdi_device; C:\windows\SysWOW64\lxdicoms.exe [517040 2007-04-26] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-03-10] ()
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [31080 2012-08-30] (AVG Technologies)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-07] (BlueStack Systems)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PcdrNdisuio; C:\Windows\SysWow64\drivers\pcdrndisuio.sys [19456 2009-12-17] (Windows (R) Codename Longhorn DDK provider)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0; \??\f:\pcdoctor\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 16:00 - 2014-11-12 16:01 - 00016940 _____ () C:\Users\Nikola\Desktop\FRST.txt
2014-11-12 15:47 - 2014-11-12 15:47 - 00064941 _____ () C:\Users\Nikola\Desktop\screen.rar
2014-11-12 12:21 - 2014-11-12 12:21 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-12 12:21 - 2014-11-12 12:21 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-12 12:21 - 2014-11-12 12:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-12 12:21 - 2014-11-12 12:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-12 12:21 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-11-12 12:21 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-11-12 12:21 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-11-12 12:19 - 2014-11-12 12:19 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Nikola\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-12 11:42 - 2014-11-12 11:42 - 00010511 _____ () C:\Users\Nikola\Desktop\Addition.rar
2014-11-12 11:35 - 2014-11-12 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
2014-11-12 11:33 - 2014-11-12 16:00 - 00000000 ____D () C:\FRST
2014-11-12 11:31 - 2014-11-12 11:32 - 02116096 _____ (Farbar) C:\Users\Nikola\Desktop\FRST64.exe
2014-11-12 09:18 - 2014-11-12 09:18 - 02140160 _____ () C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
2014-11-12 08:30 - 2014-11-12 08:30 - 00000000 ____D () C:\rsit
2014-11-12 08:20 - 2014-11-12 08:20 - 00000004 _____ () C:\Users\Nikola\AppData\Roaming\appdataFr2.bin
2014-11-10 15:13 - 2014-11-10 17:13 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-11-10 15:13 - 2014-11-10 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-11-05 19:16 - 2014-11-05 19:16 - 01485024 _____ () C:\Users\Nikola\Desktop\Nový WinRAR archiv.rar
2014-11-05 18:52 - 2014-11-05 18:52 - 00559616 _____ () C:\Users\Nikola\Desktop\5006.ppt
2014-11-05 18:52 - 2014-11-05 18:52 - 00342528 _____ () C:\Users\Nikola\Desktop\5049 (1).ppt
2014-11-05 18:51 - 2014-11-05 18:51 - 00342528 _____ () C:\Users\Nikola\Desktop\5049.ppt
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\windows\SysWOW64\CNC_BVL.dll
2014-11-04 21:58 - 2012-11-26 12:32 - 00088576 _____ () C:\windows\SysWOW64\CNC176ED.TBL
2014-11-04 21:58 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\windows\SysWOW64\CNHMCA.dll
2014-11-04 21:56 - 2014-11-04 21:56 - 00000000 ____D () C:\windows\system32\STRING
2014-11-04 21:56 - 2013-01-24 16:24 - 00359936 _____ (CANON INC.) C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:56 - 2013-01-24 16:24 - 00039424 _____ (CANON INC.) C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56 - 2013-01-24 16:23 - 00366592 _____ (CANON INC.) C:\windows\SysWOW64\CNMNPPM.DLL
2014-11-04 21:55 - 2014-11-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3500 series
2014-11-04 21:54 - 2013-04-04 05:00 - 00391168 _____ (CANON INC.) C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51 - 2014-11-04 21:51 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2014-11-04 21:48 - 2014-11-04 21:49 - 50974296 _____ () C:\Users\Nikola\Desktop\win-mg3500-1_0-mcd.exe
2014-11-04 20:14 - 2014-11-04 20:14 - 00796672 _____ () C:\Users\Nikola\Desktop\4993.ppt
2014-11-04 20:13 - 2014-11-04 20:13 - 01345536 _____ () C:\Users\Nikola\Desktop\5498.ppt
2014-11-04 19:50 - 2014-11-04 19:50 - 08658432 _____ () C:\Users\Nikola\Desktop\trávicí soustava.ppt
2014-11-03 21:15 - 2014-11-03 21:16 - 761700688 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-528.-Přesně-podle-plánu.avi
2014-11-03 19:14 - 2014-11-03 19:17 - 623009092 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-527.--Hurá-do-Egypta!-4.11.2014.avi
2014-10-31 23:08 - 2014-10-31 23:08 - 186434536 _____ () C:\Users\Nikola\Desktop\výstava.zip
2014-10-31 23:07 - 2014-10-31 23:07 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka – kopie
2014-10-31 22:58 - 2014-10-31 22:58 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka (2)
2014-10-26 07:10 - 2014-10-26 07:10 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09 - 2014-10-26 07:09 - 00000000 ___HD () C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52 - 2014-10-26 07:42 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-10-26 06:39 - 2014-11-04 22:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-10-26 06:36 - 2014-11-04 22:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-10-25 18:44 - 2014-10-31 23:05 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka
2014-10-17 22:20 - 2014-10-17 22:21 - 08219532 _____ () C:\Users\Nikola\Desktop\5351.ppt
2014-10-17 20:03 - 2014-11-10 21:04 - 00000000 ____D () C:\Users\Nikola\Desktop\septima
2014-10-16 16:25 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-16 16:25 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-16 16:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-16 16:25 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-16 16:25 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-16 16:25 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-16 16:25 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-16 16:25 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-16 16:25 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-16 16:25 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-16 16:25 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-16 16:25 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-16 16:25 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-16 16:25 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-16 16:25 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-16 16:25 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-16 16:25 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-16 16:25 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-16 16:25 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-16 16:23 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-16 16:23 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-10-16 16:23 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-16 16:23 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-16 16:23 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-10-16 16:22 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-16 16:22 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 16:00 - 2012-08-27 20:42 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter
2014-11-12 15:55 - 2010-08-25 14:39 - 02037246 _____ () C:\windows\WindowsUpdate.log
2014-11-12 14:55 - 2012-09-24 13:37 - 00000000 __SHD () C:\ProgramData\VRL
2014-11-12 12:15 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:15 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:07 - 2014-05-18 12:27 - 00003812 _____ () C:\windows\setupact.log
2014-11-12 12:07 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-12 10:23 - 2014-06-04 15:25 - 00004696 _____ () C:\windows\PFRO.log
2014-11-12 10:23 - 2014-02-02 18:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-12 10:19 - 2014-08-26 11:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-11-12 10:16 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-12 09:26 - 2013-09-10 13:19 - 00000000 ____D () C:\AdwCleaner
2014-11-12 08:30 - 2012-10-26 14:19 - 00000000 ____D () C:\Program Files\trend micro
2014-11-11 21:35 - 2012-04-21 19:39 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 21:35 - 2012-04-21 19:39 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 21:35 - 2011-06-09 20:16 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-10 15:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-10 15:14 - 2014-04-20 17:07 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-10 15:04 - 2014-04-20 17:06 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-09 19:53 - 2010-08-25 06:06 - 00682520 _____ () C:\windows\system32\perfh005.dat
2014-11-09 19:53 - 2010-08-25 06:06 - 00145906 _____ () C:\windows\system32\perfc005.dat
2014-11-09 19:53 - 2009-07-14 06:13 - 00860088 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-08 21:15 - 2012-09-29 09:43 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58 - 2009-07-14 04:20 - 00000000 __RSD () C:\windows\Media
2014-11-04 21:55 - 2011-08-13 10:16 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-11-04 21:41 - 2011-11-09 18:04 - 00000000 ____D () C:\ProgramData\Lx_cats
2014-10-31 06:25 - 2011-06-03 19:13 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40 - 2013-08-25 21:10 - 00000000 ____D () C:\filmy
2014-10-30 12:25 - 2011-05-25 22:04 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-10-28 20:30 - 2012-09-25 14:31 - 00000000 ____D () C:\Users\Guest
2014-10-28 20:30 - 2012-09-25 14:16 - 00000000 ____D () C:\Users\Next
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP140 series
2014-10-28 20:30 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-10-28 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration
2014-10-28 19:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-10-25 22:48 - 2014-08-12 20:52 - 00000000 ____D () C:\Users\Nikola\AppData\Local\Adobe
2014-10-18 02:38 - 2011-05-07 19:37 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-18 02:38 - 2011-05-07 19:37 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-18 00:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-10-17 20:18 - 2012-07-12 23:28 - 00000000 ___RD () C:\Users\Nikola\Desktop\Fotky
2014-10-17 20:13 - 2013-03-26 20:01 - 00000000 ____D () C:\Users\Nikola\Desktop\Škola
2014-10-17 18:22 - 2009-07-14 05:45 - 00441880 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-17 18:16 - 2011-05-14 12:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-17 17:39 - 2013-07-25 02:01 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 16:24 - 2011-05-29 20:29 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Nikola\Desktop" je 108602 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint
C:\Program Files (x86)\PDF24\pdf24.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE -startup [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by Nikola (administrator) on NIKOLA-PC on 12-11-2014 16:00:41
Running from C:\Users\Nikola\Desktop
Loaded Profiles: Nikola & Next & Guest (Available profiles: Nikola & Next & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
( Company (R)) C:\Windows\SysWOW64\HUAYNF~1.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
( ) C:\Windows\System32\lxdicoms.exe
() C:\Program Files (x86)\Photodex\ProShow Gold\scsiaccess.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
(Lexmark) C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-04-27] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1894696 2010-01-07] (Synaptics Incorporated)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4462496 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056800 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [lxdimon.exe] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [435120 2007-05-07] ()
HKLM\...\Run: [lxdiamon] => C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [20480 2007-03-05] (Lexmark)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-02] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [UCam_Menu] => C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM-x32\...\Run: [FaxCenterServer] => C:\Program Files (x86)\\Lexmark Fax Solutions\fm3032.exe [312240 2007-05-07] ()
HKLM-x32\...\Run: [Freecorder FLV Service] => "C:\Program Files (x86)\Freecorder\FLVSrvc.exe" /run
HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe"
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [843480 2014-10-07] (BlueStack Systems, Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2014-10-01] (Malwarebytes Corporation)
HKU\S-1-5-21-2772758291-4078256221-3500050187-1001\...\MountPoints2: E - E:\Install.exe
HKU\S-1-5-21-2772758291-4078256221-3500050187-1005\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
HKU\S-1-5-21-2772758291-4078256221-3500050187-501\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF ProfilePath: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF SearchPlugin: C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: WOT - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-02-02]
FF Extension: Seznam lištička - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2013-03-28]
FF Extension: Fotofox - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\fotofox@mozilla.com.xpi [2012-06-04]
FF Extension: FREE MP3 Search - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\search@org-com.eu.xpi [2012-06-04]
FF Extension: Black Skin - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\Extensions\{2aa024bd-65c3-4256-8343-d32e1047acff}.xpi [2013-07-04]
FF Extension: No Name - C:\Program Files (x86)\RichMediaViewV1\RichMediaViewV1release2297\ff [Not Found]
FF Extension: No Name - C:\Users\Nikola\AppData\Roaming\Mozilla\Firefox\Profiles\rrrs58j5.default\extensions\chang.gibbons98@aol.com [Not Found]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Prezentace Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-12]
CHR Extension: (Dokumenty Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-12]
CHR Extension: (Disk Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-12]
CHR Extension: (YouTube) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-12]
CHR Extension: (Vyhledávání Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-12]
CHR Extension: (Gmail) - C:\Users\Nikola\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [409304 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2014-10-07] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [782040 2014-10-07] (BlueStack Systems, Inc.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [864032 2009-08-11] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-14] ()
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 lxdi_device; C:\windows\system32\lxdicoms.exe [876976 2007-04-26] ( )
R2 lxdi_device; C:\windows\SysWOW64\lxdicoms.exe [517040 2007-04-26] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShow Gold\ScsiAccess.exe [186760 2013-03-10] ()
S2 MsgPlusService; "C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 avgtp; C:\windows\system32\drivers\avgtpx64.sys [31080 2012-08-30] (AVG Technologies)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [122072 2014-10-07] (BlueStack Systems)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 PcdrNdisuio; C:\Windows\SysWow64\drivers\pcdrndisuio.sys [19456 2009-12-17] (Windows (R) Codename Longhorn DDK provider)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
S3 PCDSRVC{A14E314B-3E985FDA-06000000}_0; \??\f:\pcdoctor\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 16:00 - 2014-11-12 16:01 - 00016940 _____ () C:\Users\Nikola\Desktop\FRST.txt
2014-11-12 15:47 - 2014-11-12 15:47 - 00064941 _____ () C:\Users\Nikola\Desktop\screen.rar
2014-11-12 12:21 - 2014-11-12 12:21 - 00129752 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-12 12:21 - 2014-11-12 12:21 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-12 12:21 - 2014-11-12 12:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-12 12:21 - 2014-11-12 12:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-12 12:21 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-11-12 12:21 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-11-12 12:21 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-11-12 12:19 - 2014-11-12 12:19 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Nikola\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-12 11:42 - 2014-11-12 11:42 - 00010511 _____ () C:\Users\Nikola\Desktop\Addition.rar
2014-11-12 11:35 - 2014-11-12 11:36 - 00112640 _____ (forum.viry.cz) C:\Users\Nikola\Desktop\FRSTLauncher (2).exe
2014-11-12 11:33 - 2014-11-12 16:00 - 00000000 ____D () C:\FRST
2014-11-12 11:31 - 2014-11-12 11:32 - 02116096 _____ (Farbar) C:\Users\Nikola\Desktop\FRST64.exe
2014-11-12 09:18 - 2014-11-12 09:18 - 02140160 _____ () C:\Users\Nikola\Desktop\adwcleaner_4.101.exe
2014-11-12 08:30 - 2014-11-12 08:30 - 00000000 ____D () C:\rsit
2014-11-12 08:20 - 2014-11-12 08:20 - 00000004 _____ () C:\Users\Nikola\AppData\Roaming\appdataFr2.bin
2014-11-10 15:13 - 2014-11-10 17:13 - 00000000 ____D () C:\Program Files (x86)\BlueStacks
2014-11-10 15:13 - 2014-11-10 15:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2014-11-05 19:16 - 2014-11-05 19:16 - 01485024 _____ () C:\Users\Nikola\Desktop\Nový WinRAR archiv.rar
2014-11-05 18:52 - 2014-11-05 18:52 - 00559616 _____ () C:\Users\Nikola\Desktop\5006.ppt
2014-11-05 18:52 - 2014-11-05 18:52 - 00342528 _____ () C:\Users\Nikola\Desktop\5049 (1).ppt
2014-11-05 18:51 - 2014-11-05 18:51 - 00342528 _____ () C:\Users\Nikola\Desktop\5049.ppt
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-11-04 21:58 - 2014-11-04 21:58 - 00000000 ____D () C:\ProgramData\Canon IJ Network Tool
2014-11-04 21:58 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\windows\SysWOW64\CNC_BVL.dll
2014-11-04 21:58 - 2012-11-26 12:32 - 00088576 _____ () C:\windows\SysWOW64\CNC176ED.TBL
2014-11-04 21:58 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\windows\SysWOW64\CNHMCA.dll
2014-11-04 21:56 - 2014-11-04 21:56 - 00000000 ____D () C:\windows\system32\STRING
2014-11-04 21:56 - 2013-01-24 16:24 - 00359936 _____ (CANON INC.) C:\windows\system32\CNMN6PPM.DLL
2014-11-04 21:56 - 2013-01-24 16:24 - 00039424 _____ (CANON INC.) C:\windows\system32\CNMN6UI.DLL
2014-11-04 21:56 - 2013-01-24 16:23 - 00366592 _____ (CANON INC.) C:\windows\SysWOW64\CNMNPPM.DLL
2014-11-04 21:55 - 2014-11-04 21:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrace uživatele zařízení Canon MG3500 series
2014-11-04 21:54 - 2013-04-04 05:00 - 00391168 _____ (CANON INC.) C:\windows\system32\CNMLMBV.DLL
2014-11-04 21:51 - 2014-11-04 21:51 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2014-11-04 21:48 - 2014-11-04 21:49 - 50974296 _____ () C:\Users\Nikola\Desktop\win-mg3500-1_0-mcd.exe
2014-11-04 20:14 - 2014-11-04 20:14 - 00796672 _____ () C:\Users\Nikola\Desktop\4993.ppt
2014-11-04 20:13 - 2014-11-04 20:13 - 01345536 _____ () C:\Users\Nikola\Desktop\5498.ppt
2014-11-04 19:50 - 2014-11-04 19:50 - 08658432 _____ () C:\Users\Nikola\Desktop\trávicí soustava.ppt
2014-11-03 21:15 - 2014-11-03 21:16 - 761700688 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-528.-Přesně-podle-plánu.avi
2014-11-03 19:14 - 2014-11-03 19:17 - 623009092 _____ () C:\Users\Nikola\Desktop\Ordinace-v-růžové-zahradě-2-527.--Hurá-do-Egypta!-4.11.2014.avi
2014-10-31 23:08 - 2014-10-31 23:08 - 186434536 _____ () C:\Users\Nikola\Desktop\výstava.zip
2014-10-31 23:07 - 2014-10-31 23:07 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka – kopie
2014-10-31 22:58 - 2014-10-31 22:58 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka (2)
2014-10-26 07:10 - 2014-10-26 07:10 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Canon
2014-10-26 07:09 - 2014-10-26 07:09 - 00000000 ___HD () C:\ProgramData\CanonIJQuickMenu
2014-10-26 06:52 - 2014-10-26 07:42 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-10-26 06:39 - 2014-11-04 22:04 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-10-26 06:36 - 2014-11-04 22:00 - 00000000 ____D () C:\Program Files (x86)\Canon
2014-10-25 18:44 - 2014-10-31 23:05 - 00000000 ____D () C:\Users\Nikola\Desktop\Nová složka
2014-10-17 22:20 - 2014-10-17 22:21 - 08219532 _____ () C:\Users\Nikola\Desktop\5351.ppt
2014-10-17 20:03 - 2014-11-10 21:04 - 00000000 ____D () C:\Users\Nikola\Desktop\septima
2014-10-16 16:25 - 2014-10-07 03:54 - 00378552 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-10-16 16:25 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-10-16 16:25 - 2014-09-29 01:58 - 03198976 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-10-16 16:25 - 2014-09-25 23:50 - 13619200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-10-16 16:25 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-10-16 16:25 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-10-16 16:25 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-10-16 16:25 - 2014-09-25 23:31 - 02108416 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-10-16 16:25 - 2014-09-19 03:25 - 23631360 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:56 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:55 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-10-16 16:25 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-10-16 16:25 - 2014-09-19 02:41 - 02796032 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00547328 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:40 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:39 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:38 - 00083968 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 02:36 - 05829632 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:31 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 02:30 - 00033792 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-10-16 16:25 - 2014-09-19 02:27 - 00595968 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-10-16 16:25 - 2014-09-19 02:26 - 00139264 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00758272 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 02:25 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-10-16 16:25 - 2014-09-19 02:18 - 00940032 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-10-16 16:25 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-10-16 16:25 - 2014-09-19 02:14 - 00446464 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-10-16 16:25 - 2014-09-19 02:06 - 00072704 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00195584 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-10-16 16:25 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2014-10-16 16:25 - 2014-09-19 02:00 - 00085504 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-10-16 16:25 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2014-10-16 16:25 - 2014-09-19 01:58 - 00289280 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-10-16 16:25 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-10-16 16:25 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-10-16 16:25 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-10-16 16:25 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2014-10-16 16:25 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2014-10-16 16:25 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00731136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:42 - 00710656 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-10-16 16:25 - 2014-09-19 01:40 - 01249280 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-16 16:25 - 2014-09-19 01:33 - 02309632 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-10-16 16:25 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-10-16 16:25 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-10-16 16:25 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2014-10-16 16:25 - 2014-09-19 01:14 - 01447936 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-10-16 16:25 - 2014-09-19 00:59 - 00775168 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-10-16 16:25 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-10-16 16:25 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01943696 _____ (Microsoft Corporation) C:\windows\system32\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\windows\SysWOW64\dfshim.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00156312 _____ (Microsoft Corporation) C:\windows\system32\mscorier.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\windows\SysWOW64\mscories.dll
2014-10-16 16:25 - 2014-06-18 23:23 - 00073880 _____ (Microsoft Corporation) C:\windows\system32\mscories.dll
2014-10-16 16:23 - 2014-09-04 06:23 - 00424448 _____ (Microsoft Corporation) C:\windows\system32\rastls.dll
2014-10-16 16:23 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\windows\SysWOW64\rastls.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 03722240 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 01118720 _____ (Microsoft Corporation) C:\windows\system32\mstsc.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00681984 _____ (Microsoft Corporation) C:\windows\system32\termsrv.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00455168 _____ (Microsoft Corporation) C:\windows\system32\winlogon.exe
2014-10-16 16:23 - 2014-07-17 03:07 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\winsta.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00150528 _____ (Microsoft Corporation) C:\windows\system32\rdpcorekmts.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 03:07 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\windows\SysWOW64\winsta.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 03221504 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 01051136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstsc.exe
2014-10-16 16:23 - 2014-07-17 02:39 - 00131584 _____ (Microsoft Corporation) C:\windows\SysWOW64\aaclient.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2014-10-16 16:23 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2014-10-16 16:23 - 2014-07-17 02:21 - 00212480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rdpwd.sys
2014-10-16 16:23 - 2014-07-17 02:21 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tssecsrv.sys
2014-10-16 16:23 - 2014-05-30 09:08 - 00340992 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00314880 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00307200 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 09:08 - 00210944 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00259584 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00247808 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00220160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2014-10-16 16:23 - 2014-05-30 08:52 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2014-10-16 16:22 - 2014-09-13 02:58 - 00077312 _____ (Microsoft Corporation) C:\windows\system32\packager.dll
2014-10-16 16:22 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\windows\SysWOW64\packager.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-12 16:00 - 2012-08-27 20:42 - 00000000 ____D () C:\ProgramData\YTD YouTube Downloader & Converter
2014-11-12 15:55 - 2010-08-25 14:39 - 02037246 _____ () C:\windows\WindowsUpdate.log
2014-11-12 14:55 - 2012-09-24 13:37 - 00000000 __SHD () C:\ProgramData\VRL
2014-11-12 12:15 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:15 - 2009-07-14 05:45 - 00013632 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-12 12:07 - 2014-05-18 12:27 - 00003812 _____ () C:\windows\setupact.log
2014-11-12 12:07 - 2009-07-14 06:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-11-12 10:23 - 2014-06-04 15:25 - 00004696 _____ () C:\windows\PFRO.log
2014-11-12 10:23 - 2014-02-02 18:01 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-11-12 10:19 - 2014-08-26 11:21 - 00000000 ____D () C:\Users\Guest\AppData\Local\Google
2014-11-12 10:16 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-11-12 10:16 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-11-12 09:26 - 2013-09-10 13:19 - 00000000 ____D () C:\AdwCleaner
2014-11-12 08:30 - 2012-10-26 14:19 - 00000000 ____D () C:\Program Files\trend micro
2014-11-11 21:35 - 2012-04-21 19:39 - 00701104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-11-11 21:35 - 2012-04-21 19:39 - 00003852 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-11-11 21:35 - 2011-06-09 20:16 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-10 15:16 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-10 15:14 - 2014-04-20 17:07 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-10 15:04 - 2014-04-20 17:06 - 00000000 ____D () C:\ProgramData\BlueStacksSetup
2014-11-09 19:53 - 2010-08-25 06:06 - 00682520 _____ () C:\windows\system32\perfh005.dat
2014-11-09 19:53 - 2010-08-25 06:06 - 00145906 _____ () C:\windows\system32\perfc005.dat
2014-11-09 19:53 - 2009-07-14 06:13 - 00860088 _____ () C:\windows\system32\PerfStringBackup.INI
2014-11-08 21:15 - 2012-09-29 09:43 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\vlc
2014-11-04 21:58 - 2009-07-14 04:20 - 00000000 __RSD () C:\windows\Media
2014-11-04 21:55 - 2011-08-13 10:16 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-11-04 21:41 - 2011-11-09 18:04 - 00000000 ____D () C:\ProgramData\Lx_cats
2014-10-31 06:25 - 2011-06-03 19:13 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\uTorrent
2014-10-30 15:40 - 2013-08-25 21:10 - 00000000 ____D () C:\filmy
2014-10-30 12:25 - 2011-05-25 22:04 - 00275080 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2014-10-28 20:30 - 2012-09-25 14:31 - 00000000 ____D () C:\Users\Guest
2014-10-28 20:30 - 2012-09-25 14:16 - 00000000 ____D () C:\Users\Next
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\windows\system32\CanonIJ Uninstaller Information
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-10-28 20:30 - 2011-08-13 10:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MP140 series
2014-10-28 20:30 - 2011-05-07 13:32 - 00000000 ____D () C:\Users\Nikola\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2014-10-28 20:30 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\registration
2014-10-28 19:37 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\system32\NDF
2014-10-25 22:48 - 2014-08-12 20:52 - 00000000 ____D () C:\Users\Nikola\AppData\Local\Adobe
2014-10-18 02:38 - 2011-05-07 19:37 - 00003948 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-18 02:38 - 2011-05-07 19:37 - 00003696 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-18 00:31 - 2009-07-14 04:20 - 00000000 ____D () C:\windows\rescache
2014-10-17 20:18 - 2012-07-12 23:28 - 00000000 ___RD () C:\Users\Nikola\Desktop\Fotky
2014-10-17 20:13 - 2013-03-26 20:01 - 00000000 ____D () C:\Users\Nikola\Desktop\Škola
2014-10-17 18:22 - 2009-07-14 05:45 - 00441880 _____ () C:\windows\system32\FNTCACHE.DAT
2014-10-17 18:16 - 2011-05-14 12:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-17 17:39 - 2013-07-25 02:01 - 00000000 ____D () C:\windows\system32\MRT
2014-10-17 16:24 - 2011-05-29 20:29 - 103265616 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Nikola\Desktop" je 108602 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_FB70C58CB820D70F1EC285ADB1114529
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDFPrint
C:\Program Files (x86)\PDF24\pdf24.exe
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE
C:\Program Files\PowerISO\PWRISOVM.EXE -startup [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk
C:\PROGRA~1\Lenovo\BLUETO~1\BTTray.exe
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================