Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nové, nechtěné programy v compu, FF- zaplněná op. paměť

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Hooker
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 29 úno 2008 02:26
Bydliště: Čáslav

Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#1 Příspěvek od Hooker »

Zdravím příznivce fora a prosím o pomoc.Na ploše se objevilo: ExpressFiles, Continue App of The Day, ve složce %Appdata%\Local\Temp\DownloadManager, Launcher_i14094491.exe
%ProgramFiles% - -složka Seznam.cz - něco jsem odinstaloval, něco vyhodil a spustil Adwcleaner - posílám log a taky RSIT

Log z Adwcleaner:
# AdwCleaner v4.001 - Report created 23/10/2014 at 22:36:28
# DB v
# Updated 20/10/2014 by Xplode
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Jirka - JIRKA-PC
# Running from : C:\Users\Jirka\Desktop\adwcleaner_4.001.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Users\Jirka\AppData\Roaming\DriverCure
Folder Deleted : C:\ProgramData\ParetoLogic
Folder Deleted : C:\Users\Jirka\AppData\Roaming\ParetoLogic

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16584


-\\ Mozilla Firefox v32.0.3 (x86 cs)


-\\ Google Chrome v


*************************

AdwCleaner[R0].txt - [12011 octets] - [11/11/2013 02:17:04]
AdwCleaner[R1].txt - [1446 octets] - [23/10/2014 22:32:15]
AdwCleaner[S0].txt - [12327 octets] - [11/11/2013 02:21:15]
AdwCleaner[S1].txt - [1378 octets] - [23/10/2014 22:36:28]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1438 octets] ##########
# AdwCleaner v4.101 - Report created 22/11/2014 at 22:44:16
# Updated 09/11/2014 by Xplode
# Database : 2014-11-16.1 [Live]
# Operating System : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
# Username : Jirka - JIRKA-PC
# Running from : C:\Users\Jirka\Desktop\adwcleaner_4.101.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\globalUpdate
Folder Deleted : C:\Program Files\SavePass 1.1
Folder Deleted : C:\Users\Jirka\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Jirka\AppData\Roaming\ExpressFiles

***** [ Scheduled Tasks ] *****

Task Deleted : AmiUpdXp
Task Deleted : Express FilesUpdate
Task Deleted : 05a649d6-aad9-400c-9df9-46ce41102645
Task Deleted : 5e9ce7f9-591d-4c13-889b-fdd543f540a0
Task Deleted : bd2fbff8-0251-4c92-99af-90f7dee50b70-1
Task Deleted : bd2fbff8-0251-4c92-99af-90f7dee50b70-11
Task Deleted : bd2fbff8-0251-4c92-99af-90f7dee50b70-4
Task Deleted : bd2fbff8-0251-4c92-99af-90f7dee50b70-5
Task Deleted : bd2fbff8-0251-4c92-99af-90f7dee50b70-5_user

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Key Deleted : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622342229}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655345529}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666346629}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644344429}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\dt soft\daemon tools toolbar
Key Deleted : HKCU\Software\ExpressFiles
Key Deleted : HKCU\Software\GlobalUpdate
Key Deleted : HKCU\Software\InstalledBrowserExtensions
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\SavePass 1.1
Key Deleted : HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Key Deleted : HKLM\SOFTWARE\ExpressFiles
Key Deleted : HKLM\SOFTWARE\GlobalUpdate
Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
Key Deleted : HKLM\SOFTWARE\SavePass 1.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ExpressFiles
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SavePass 1.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16592


-\\ Mozilla Firefox v33.1 (x86 cs)


-\\ Google Chrome v


-\\ Opera v0.0.0.0


*************************

AdwCleaner[R0].txt - [12011 octets] - [11/11/2013 01:17:04]
AdwCleaner[R1].txt - [9778 octets] - [23/10/2014 21:32:15]
AdwCleaner[R2].txt - [8392 octets] - [22/11/2014 22:41:27]
AdwCleaner[S0].txt - [12327 octets] - [11/11/2013 01:21:15]
AdwCleaner[S1].txt - [9622 octets] - [23/10/2014 21:36:28]
AdwCleaner[S2].txt - [1518 octets] - [23/10/2014 21:43:44]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [9742 octets] ##########

Log RSIT:
Logfile of random's system information tool 1.09 (written by random/random)
Run by Jirka at 2014-11-23 00:07:10
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 41 GB (34%) free of 119 GB
Total RAM: 2047 MB (40% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 0:07:26, on 23.11.2014
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16592)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\WTMKM.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
C:\Users\Jirka\Desktop\CLEAN\RSIT.exe
C:\Program Files\Trend Micro\Jirka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: eee1ef70083a013208d37190b1a6e5ef0063429 - {11111111-1111-1111-1111-110611341129} - (no file)
O2 - BHO: (no name) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [MacrokeyManager] WTMKM.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [UIWatcher] C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\RunOnce: [SeznamInstall-uninstall:f66561a164761bff01c739f48e378103] "C:\Users\Jirka\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe" -c "C:\Users\Jirka\AppData\Roaming\Seznam.cz"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Download all by FlashGet3 - C:\Program Files\FlashGet Network\FlashGet 3\GetAllUrl.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Sony Ericsson OMSI download service (OMSI download service) - Unknown owner - C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: WTService - Unknown owner - C:\Windows\system32\atwtusb.exe

--
End of file - 6156 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job

=========Mozilla firefox=========

ProfilePath - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808

prefs.js - "browser.startup.homepage" - "http://www.centrum.cz/"

"{20a82645-c095-46ed-80e3-08825760534b}"=C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"{ABDE892B-13A8-4d1b-88E6-365A6E755758}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
"{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 15.0.0.223 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0]
"Description"=DivX® Player Plugin for VOD Content
"Path"=C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0]
"Description"=DivX VOD Helper Plug-in
"Path"=C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Web Player Plug-In,version=1.0.0]
"Description"=DivX Web Player
"Path"=C:\Program Files\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=10.51.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=10.51.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WPF,version=3.5]
"Description"=Windows Presentation Foundation plug-in for Mozilla browsers
"Path"=c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nppl3260;version=16.0.3.51]
"Description"=RealPlayer(tm) LiveConnect-Enabled Plug-In
"Path"=c:\program files\real\realplayer\Netscape6\nppl3260.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.3]
"Description"=RealNetworks(tm) RealDownloader Peppe rFlash Video Shim Plug-In
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@real.com/nprpplugin;version=16.0.3.51]
"Description"=RealPlayer Download Plugin
"Path"=c:\program files\real\realplayer\Netscape6\nprpplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@realnetworks.com/npdlplugin;version=1]
"Description"=RealDownloader Plugin
"Path"=C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2013-12-18 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-11-21 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-12-18 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MacrokeyManager"=C:\Windows\system32\WTMKM.exe [2011-06-01 7144448]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2014-11-21 5226600]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]
"NvBackend"=C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2013-12-10 2279712]
"TkBellExe"=C:\Program Files\real\realplayer\update\realsched.exe [2014-09-22 295512]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2014-10-02 421888]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"UIWatcher"=C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe [2010-02-09 3509080]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2014-10-30 4826904]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SeznamInstall-uninstall:f66561a164761bff01c739f48e378103"=C:\Users\Jirka\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe [2014-11-22 534528]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21 959904]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2013-09-13 59720]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXMediaServer]
C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [2013-09-11 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
C:\Program Files\DivX\DivX Update\DivXUpdate.exe [2013-08-29 1861968]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-03-12 6965792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\real\realplayer\update\realsched.exe [2014-09-22 295512]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe"="C:\Program Files\FlashGet Network\FlashGet 3\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"msacm.l3acm"=l3codecp.acm
"vidc.cvid"=iccvid.dll
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"vidc.asv2"=asusasv2.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"vidc.XVID"=xvidvfw.dll
"vidc.ffds"=C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.DIVX"=DivX.dll
"vidc.yv12"=DivX.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.YVU9"=tsbyuv.dll
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2014-11-22 23:56:03 ----D---- C:\rsit
2014-11-22 22:58:21 ----D---- C:\ProgramData\HP Product Assistant
2014-11-22 21:48:02 ----A---- C:\Windows\system32\drivers\mwac.sys
2014-11-22 21:48:02 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2014-11-22 21:48:01 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2014-11-22 21:17:56 ----D---- C:\Users\Jirka\AppData\Roaming\HpUpdate
2014-11-21 19:59:47 ----D---- C:\Program Files\Hewlett-Packard
2014-11-21 19:41:25 ----A---- C:\Windows\hpoins12.dat
2014-11-21 14:26:33 ----D---- C:\Users\Jirka\AppData\Roaming\HP
2014-11-21 10:46:10 ----D---- C:\Program Files\Seznam.cz
2014-11-21 10:18:01 ----D---- C:\ProgramData\HPSSUPPLY
2014-11-21 10:15:41 ----D---- C:\ProgramData\Hewlett-Packard
2014-11-21 10:14:53 ----A---- C:\Windows\system32\hpzids01.dll
2014-11-21 10:03:36 ----D---- C:\ProgramData\HP
2014-11-21 08:17:27 ----D---- C:\Program Files\Common Files\HP
2014-11-21 07:52:29 ----A---- C:\Windows\system32\aswBoot.exe
2014-11-21 07:52:26 ----A---- C:\Windows\avastSS.scr
2014-11-20 10:02:47 ----D---- C:\ProgramData\Apple Computer
2014-11-20 09:40:42 ----A---- C:\Windows\system32\kerberos.dll
2014-11-14 08:37:26 ----D---- C:\Program Files\Mozilla Firefox
2014-11-13 18:29:19 ----A---- C:\Windows\system32\mscories.dll
2014-11-13 18:29:19 ----A---- C:\Windows\system32\mscorier.dll
2014-11-13 18:29:19 ----A---- C:\Windows\system32\dfshim.dll
2014-11-13 18:27:56 ----A---- C:\Windows\system32\msaudite.dll
2014-11-13 18:27:53 ----A---- C:\Windows\system32\adtschema.dll
2014-11-13 18:27:49 ----A---- C:\Windows\system32\termsrv.dll
2014-11-13 18:27:49 ----A---- C:\Windows\system32\lsasrv.dll
2014-11-13 18:25:02 ----A---- C:\Windows\system32\msxml3r.dll
2014-11-13 18:25:02 ----A---- C:\Windows\system32\msxml3.dll
2014-11-13 18:24:17 ----A---- C:\Windows\system32\schannel.dll
2014-11-13 18:23:56 ----A---- C:\Windows\system32\packager.dll
2014-11-13 18:23:26 ----A---- C:\Windows\system32\IMJP10K.DLL
2014-11-13 18:21:38 ----A---- C:\Windows\system32\audiosrv.dll
2014-11-13 18:21:38 ----A---- C:\Windows\system32\AudioEng.dll
2014-11-13 18:21:37 ----A---- C:\Windows\system32\EncDump.dll
2014-11-13 18:21:37 ----A---- C:\Windows\system32\AUDIOKSE.dll
2014-11-13 18:21:19 ----A---- C:\Windows\system32\oleaut32.dll
2014-11-13 18:21:02 ----A---- C:\Windows\system32\drivers\fastfat.sys
2014-11-13 18:11:57 ----A---- C:\Windows\system32\win32k.sys
2014-11-13 18:05:02 ----A---- C:\Windows\system32\vbscript.dll
2014-11-13 18:05:02 ----A---- C:\Windows\system32\msfeedssync.exe
2014-11-13 18:05:02 ----A---- C:\Windows\system32\jsproxy.dll
2014-11-13 18:05:01 ----A---- C:\Windows\system32\urlmon.dll
2014-11-13 18:05:01 ----A---- C:\Windows\system32\mshta.exe
2014-11-13 18:05:01 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-11-13 18:05:01 ----A---- C:\Windows\system32\dxtmsft.dll
2014-11-13 18:05:00 ----A---- C:\Windows\system32\msfeeds.dll
2014-11-13 18:05:00 ----A---- C:\Windows\system32\jscript.dll
2014-11-13 18:04:59 ----A---- C:\Windows\system32\iertutil.dll
2014-11-13 18:04:58 ----A---- C:\Windows\system32\wininet.dll
2014-11-13 18:04:58 ----A---- C:\Windows\system32\url.dll
2014-11-13 18:04:58 ----A---- C:\Windows\system32\ieUnatt.exe
2014-11-13 18:04:58 ----A---- C:\Windows\system32\ieui.dll
2014-11-13 18:04:58 ----A---- C:\Windows\system32\dxtrans.dll
2014-11-13 18:04:57 ----A---- C:\Windows\system32\ieframe.dll
2014-11-13 18:04:50 ----A---- C:\Windows\system32\mshtmled.dll
2014-11-13 18:04:49 ----A---- C:\Windows\system32\jscript9.dll
2014-11-13 18:04:48 ----A---- C:\Windows\system32\mshtml.dll
2014-11-13 10:09:33 ----D---- C:\Program Files\Common Files\Java(75)
2014-11-12 19:50:48 ----D---- C:\Program Files\QuickTime(119)

======List of files/folders modified in the last 1 month======

2014-11-23 00:07:13 ----D---- C:\Program Files\Trend Micro
2014-11-23 00:07:07 ----D---- C:\Windows\temp
2014-11-22 23:07:57 ----SHD---- C:\System Volume Information
2014-11-22 22:58:58 ----SHD---- C:\Windows\Installer
2014-11-22 22:58:39 ----AD---- C:\Windows\System32
2014-11-22 22:58:21 ----D---- C:\ProgramData
2014-11-22 22:48:53 ----D---- C:\Windows\system32\Tasks
2014-11-22 22:47:42 ----A---- C:\Windows\win.ini
2014-11-22 22:46:35 ----D---- C:\Windows\system32\drivers
2014-11-22 22:44:42 ----D---- C:\AdwCleaner
2014-11-22 22:44:17 ----D---- C:\Program Files
2014-11-22 21:48:01 ----D---- C:\ProgramData\Malwarebytes
2014-11-22 10:28:06 ----D---- C:\Users\Jirka\AppData\Roaming\Image Zone Express
2014-11-21 22:08:45 ----D---- C:\Windows\Prefetch
2014-11-21 22:05:10 ----D---- C:\Windows
2014-11-21 22:02:33 ----D---- C:\Windows\system32\catroot2
2014-11-21 21:42:25 ----D---- C:\Program Files\Common Files
2014-11-21 21:13:20 ----D---- C:\Windows\Tasks
2014-11-21 21:12:29 ----D---- C:\Program Files\Google
2014-11-21 20:02:43 ----D---- C:\Windows\winsxs
2014-11-21 19:59:53 ----D---- C:\Windows\twain_32
2014-11-21 19:54:42 ----D---- C:\Windows\inf
2014-11-21 19:36:31 ----D---- C:\Users\Jirka\AppData\Roaming\Printer Info Cache
2014-11-21 14:37:22 ----D---- C:\Windows\system32\catroot
2014-11-21 10:22:36 ----D---- C:\Program Files\HP
2014-11-21 09:35:51 ----HD---- C:\Program Files\InstallShield Installation Information
2014-11-21 08:02:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-20 22:53:48 ----D---- C:\Users\Jirka\AppData\Roaming\Media Player Classic
2014-11-20 10:03:32 ----D---- C:\Program Files\QuickTime
2014-11-16 22:22:28 ----D---- C:\Program Files\CCleaner
2014-11-16 20:38:59 ----D---- C:\Windows\Microsoft.NET
2014-11-16 20:36:22 ----RSD---- C:\Windows\assembly
2014-11-16 16:57:29 ----D---- C:\Program Files\Mozilla Maintenance Service
2014-11-14 06:50:11 ----D---- C:\Windows\rescache
2014-11-13 21:33:38 ----D---- C:\Windows\system32\cs-CZ
2014-11-13 21:33:36 ----D---- C:\Windows\system32\migration
2014-11-13 21:33:36 ----D---- C:\Program Files\Internet Explorer
2014-11-13 21:23:58 ----D---- C:\Program Files\Opera
2014-11-13 19:44:30 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2014-11-13 18:17:58 ----D---- C:\Windows\system32\MRT
2014-11-13 17:43:15 ----D---- C:\Windows\system32\config
2014-11-13 17:41:51 ----D---- C:\Windows\system32\spool
2014-11-13 17:41:51 ----D---- C:\Windows\system32\drivers\etc
2014-11-13 17:41:51 ----D---- C:\Windows\system32\CodeIntegrity
2014-11-13 17:41:35 ----D---- C:\Users\Jirka\AppData\Roaming\x2xsoft
2014-11-13 17:41:35 ----D---- C:\Users\Jirka\AppData\Roaming\vlc
2014-11-13 17:41:35 ----D---- C:\Users\Jirka\AppData\Roaming\uTorrent
2014-11-13 17:41:35 ----D---- C:\Users\Jirka\AppData\Roaming\Skype
2014-11-13 17:41:33 ----D---- C:\Users\Jirka\AppData\Roaming\BITS
2014-11-13 17:41:29 ----D---- C:\ProgramData\Tablet
2014-11-13 17:41:29 ----D---- C:\ProgramData\DivX
2014-11-13 17:41:19 ----D---- C:\Program Files\Java
2014-11-13 17:41:19 ----D---- C:\Program Files\Internet Download Manager
2014-11-13 17:41:18 ----D---- C:\Program Files\DivX
2014-11-13 17:41:16 ----D---- C:\Program Files\Common Files\Java
2014-11-13 17:40:38 ----D---- C:\Windows\registration
2014-11-13 17:40:33 ----D---- C:\ProgramData\Real
2014-11-13 16:44:21 ----D---- C:\Windows\system32\Msdtc
2014-11-13 16:44:18 ----D---- C:\Windows\system32\wbem
2014-11-13 10:08:14 ----D---- C:\ProgramData\Oracle
2014-11-04 14:30:58 ----N---- C:\Windows\system32\MpSigStub.exe
2014-11-01 12:31:26 ----D---- C:\Program Files\Common Files\Adobe AIR
2014-10-31 23:25:42 ----A---- C:\Windows\system32\mrt.exe
2014-10-26 23:17:33 ----D---- C:\Windows\cs-CZ

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-11-21 49944]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-11-21 206248]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-05-10 691696]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2014-11-21 55240]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-11-22 787800]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-11-21 423784]
R1 aswTdi;aswTdi; C:\Windows\system32\drivers\aswTdi.sys [2014-11-21 57928]
R1 EIO;EIO; \??\C:\Windows\system32\drivers\EIO.sys [2006-06-14 12288]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-11-21 24184]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-11-21 70384]
R3 3xHybrid;3xHybrid service; C:\Windows\system32\DRIVERS\3xHybrid.sys [2007-04-20 674048]
R3 ASUSVRC;ASUSTeK Virtual Capture Device; C:\Windows\system32\DRIVERS\AsusVRC.sys [2007-01-29 18432]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-03-12 2342688]
R3 ip100Avista;TP-LINK 10/100Mbps PCI Network Adapter NT Driver; C:\Windows\system32\DRIVERS\ipfnd51.sys [2010-11-23 31232]
R3 moufiltr;Tablet Mouse Filter Driver; C:\Windows\system32\DRIVERS\moufiltr.sys [2009-03-08 6144]
R3 MSPQM;Server proxy správce kvality datových proudů Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2013-12-19 10471712]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2006-11-02 44544]
R3 seehcri;Sony Ericsson seehcri Device Driver; C:\Windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
R3 vhidmini;Generic Virtual HID Driver; C:\Windows\system32\DRIVERS\walvhid.sys [2009-08-20 6144]
R3 WudfPf;@%SystemRoot%\system32\drivers\Wudfpf.sys,-1000; C:\Windows\system32\drivers\WudfPf.sys [2012-07-26 66560]
S3 anvb4arn;anvb4arn; C:\Windows\system32\drivers\anvb4arn.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 Dot4;Ovladač MS IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Ovladač třídy tiskárny standardu IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Dekodér zvuků DRM jádra společnosti Microsoft; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 ggflt;SEMC USB Flash Driver Filter; C:\Windows\system32\DRIVERS\ggflt.sys [2009-07-25 13224]
S3 ggsemc;SEMC USB Flash Driver; C:\Windows\system32\DRIVERS\ggsemc.sys [2009-07-25 25512]
S3 GMSIPCI;GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
S3 HdAudAddService;Ovladač funkce Microsoft 1.1 UAA pro službu zvuku High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2009-04-11 236544]
S3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtport.sys []
S3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbus.sys []
S3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmodem.sys []
S3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2014-10-01 23256]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2014-10-01 51928]
S3 MSKSSRV;Server proxy služby datových proudů Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Server proxy hodin datových proudů Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSTEE;Konvertor jímka-jímka typu T datových proudů Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 NTACCESS;NTACCESS; \??\E:\NTACCESS.sys []
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2009-06-15 47360]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM); C:\Windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS); C:\Windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM); C:\Windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
S3 se3ebus;Sony Ericsson Device 062 (WDM); C:\Windows\system32\DRIVERS\se3ebus.sys [2007-04-10 83080]
S3 se3emdfl;Sony Ericsson Device 062 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\se3emdfl.sys [2007-04-10 15112]
S3 se3emdm;Sony Ericsson Device 062 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\se3emdm.sys [2007-04-10 108552]
S3 se3emgmt;Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\se3emgmt.sys [2007-04-10 100360]
S3 se3eobex;Sony Ericsson Device 062 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\se3eobex.sys [2007-04-10 98568]
S3 SetupNTGLM7X;SetupNTGLM7X; \??\E:\NTGLM7X.sys []
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys [2011-04-27 13056]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys [2011-04-27 20864]
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys [2011-04-27 25216]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 35328]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 27648]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2012-07-26 155136]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2013-12-18 65432]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-11-21 50344]
R2 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-10-20 71096]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [2013-12-10 1494304]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-12-19 664352]
R2 OMSI download service;Sony Ericsson OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2011-11-05 75136]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [2013-08-14 39056]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 1710464]
R2 WTService;WTService; C:\Windows\system32\atwtusb.exe [2011-04-27 871936]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2014-10-01 968504]
S2 MBAMScheduler;MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [2014-10-01 1871160]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-13 267440]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2013-09-11 46688]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe [2014-11-07 114288]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2013-09-11 770168]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

díky
MS Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika), Genuine Intel CPU2140@ 1.60GHz, 2.00GB RAM , NVIDIA GeForce 9400 GT

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#2 Příspěvek od vyosek »

Zdravim :)

:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    emptyclsid;
    iedefaults;
    FFdefaults;
    CHRdefaults;
    emptyalltemp;
    resethosts;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hooker
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 29 úno 2008 02:26
Bydliště: Čáslav

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#3 Příspěvek od Hooker »

Tak tady to je

Zoek.exe v5.0.0.0 Updated 21-11-2014
Tool run by Jirka on ne 23.11.2014 at 9:18:08,22.
Microsoft® Windows Vista™ Home Premium 6.0.6002 Service Pack 2 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Jirka\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

23.11.2014 9:19:46 Zoek.exe System Restore Point Created Succesfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b6709641-634b-4468-b3e9-d96b7513fc3a} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BFE68E-E335-4C86-BDFC-9F83ABB52262} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C763B4BC-18C4-44FB-814B-13B1E352FF3} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD30CDF-5E98-4B5D-8AF4-2453AEE0E72A} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2805279-247d-4dd7-ab05-e46d2e602522} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F02FACD7-E2F4-436D-A58D-847D3994F68A} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611341129} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b6709641-634b-4468-b3e9-d96b7513fc3a} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2805279-247d-4dd7-ab05-e46d2e602522} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\prefs.js:
user_pref("browser.startup.homepage", "http://www.centrum.cz/");

Added to C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);

ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808

user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----

prefs_23.11.2014_0939_.backup

==== Deleting Files \ Folders ======================

C:\Windows\system32\appdata deleted
C:\Program Files\Java deleted
C:\Users\Jirka\AppData\Local\7996 deleted
C:\Program Files\Mozilla Firefox\defaults\preferences\pref.js deleted
C:\Program Files\Internet Download Manager deleted
C:\PROGRA~2\hpe4A39.dll deleted
C:\PROGRA~2\hpeBEDA.dll deleted
C:\Users\Jirka\AppData\LocalLow\boost_interprocess deleted
C:\Windows\system32\config\systemprofile\Searches deleted
C:\Windows\system32\GroupPolicy\Machine deleted
C:\Windows\system32\GroupPolicy\User deleted
C:\Windows\system32\GroupPolicy\gpt.ini deleted
"C:\Users\Jirka\AppData\Roaming\f$f" deleted
"C:\Users\Jirka\AppData\Roaming\Faces\Faces.prf" deleted
"C:\Users\Jirka\AppData\Roaming\Vso" deleted
"C:\Users\Jirka\AppData\Roaming\Faces" deleted

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}"="C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext" [09.09.2013 13:00]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808
- Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
- RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
- Undetermined - {20a82645-c095-46ed-80e3-08825760534b}
- Undetermined - {35106bca-6c78-48c7-ac28-56df30b51d2a}
- Undetermined - {DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}
- Google Translator - %ProfilePath%\extensions\jid1-dgnIBwQga0SIBw@jetpack.xpi
- Linkification - %ProfilePath%\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi
- BugMeNot Plugin - %ProfilePath%\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Open With Photoshop - %ProfilePath%\extensions\{f3f219f9-cbce-467e-b8fe-6e076d29665c}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808
559E8D42BE485208F1C4BB294D6840A4 - C:\Program Files\QuickTime\Plugins\npqtplugin5.dll - QuickTime Plug-in 7.7.6
5D4279248A0E506CF007BD51EBF74CEA - C:\Program Files\QuickTime\Plugins\npqtplugin4.dll - QuickTime Plug-in 7.7.6
F9DE379CE8A782530A4FA0B731F3A49B - C:\Program Files\QuickTime\Plugins\npqtplugin3.dll - QuickTime Plug-in 7.7.6
049BD7AD3B94F24FA274ED1F7FC5871B - C:\Program Files\QuickTime\Plugins\npqtplugin2.dll - QuickTime Plug-in 7.7.6
D937A4645EFF8CB4F123E3C899C052B2 - C:\Program Files\QuickTime\Plugins\npqtplugin.dll - QuickTime Plug-in 7.7.6
67D325B5AEB28E381B84E8DE1A90C7A8 - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll - Shockwave Flash
3A9E1940B4459CC97FDCBB24FCB69004 - c:\program files\real\realplayer\Netscape6\nppl3260.dll - RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit)
0FCEAA7D12B7B0BA825E5C770B1DCA48 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll - RealPlayer Download Plugin
5232105D125A448E99D8C905AB4713EE - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll - Adobe Acrobat
21536AF136F35D9E960B085C905C98FB - C:\Program Files\Adobe\Reader 10.0\Reader\browser\nppdf32.dll - Adobe Acrobat
893BF7D2261C56C24F813405D9D018E0 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll - Silverlight Plug-In
0CA4180B21C6B728578F3B0433BB740E - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
D10D54424F7388DA2C8BF9877DF8A287 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Plus Web Player
C2321043FA2CA4C32FF449DE6116B5D9 - C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll - Shockwave for Director / Shockwave for Director
86244E1B6D062BBE2B91AA5DA7376806 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll - DivX VOD Helper Plug-in
BE126CB7049E89ED6F3038016668B502 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll - RealNetworks(tm) RealDownloader Chrome Background Extension Plug-In (32-bit)
EAC427FEF96A13058C1ACD17C38966CF - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll - RealNetworks(tm) RealDownloader PepperFlashVideoShim Plug-In (32-bit)
96B3689320E9B16EDF38B7A5001C35F0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll - RealNetworks(tm) RealDownloader HTML5VideoShim Plug-In (32-bit)
F8CB60A5ACA5D73807ECBD9942A8BCB7 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll - RealDownloader Plugin
AB87EEFFD18F2BAAFC274E7075EA6C67 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - Windows Presentation Foundation / Windows Presentation Foundation
8DA2ED6B04EA33F2EAE8BA883F903729 - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrlui.dll - Microsoft® Silverlight


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[21.11.2014 07:52]
idhngdhcfkoamngbedgpaokgjbnpdiji - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx[14.08.2013 14:24]

Docs - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake
RealDownloader - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji
RealPlayer HTML5Video Downloader Extension - Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk
SavePass 1.1 - Jirka\AppData\Roaming\Opera Software\Opera Stable\Extensions\ilhhefepljbmehhbmjcflhcchkddfaon

==== Chromium Startpages ======================

C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences
:"DK/NycnagWI3rmvsO6mVJw=="},"pinned_tabs":[],"plugins":{"migrated_to_pepper_flash":true,"plugins_list":[],"removed_old_component_pepper_flash_settings":true},"profile":{"avatar_index":0,"content_settings":{"clear_on_exit_migrated":true,"pattern_pairs":{},"pref_version":1},"exit_type":"Normal","exited_cleanly":true,"icon_version":2,"managed_user_id":"","name":"Prvn\u00ED u\u017Eivatel","per_host_zoom_levels":{}},"session":{"restore_on_startup":4,"restore_on_startup_migrated":true,"startup_urls":["http://www.google.com/"],"startup_urls_migration_time":"13049033110619930"},"sync_promo":{"show_on_first_run_allowed":false},"translate_blocked_languages":["cs"],"translate_whitelists":{}}


==== Chromium Fix ======================

C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk deleted successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Extensions\ilhhefepljbmehhbmjcflhcchkddfaon deleted successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_ilhhefepljbmehhbmjcflhcchkddfaon_0.localstorage deleted successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Local Storage\chrome-extension_ilhhefepljbmehhbmjcflhcchkddfaon_0.localstorage-journal deleted successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\databases\chrome-extension_ilhhefepljbmehhbmjcflhcchkddfaon_0 deleted successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Local Extension Settings\ilhhefepljbmehhbmjcflhcchkddfaon deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.centrum.cz/"
"Search Page"="http://www.bing.com/search?q={searchTer ... DF&PC=AV01"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://www.bing.com/search?q={searchTer ... DF&PC=AV01"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="about:newtab"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://www.centrum.cz/"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
"Tabs"="res://ieframe.dll/tabswelcome.htm"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{632F07F3-19A1-4d16-A23F-E6CE9486BAB5}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{632F07F3-19A1-4d16-A23F-E6CE9486BAB5} Microsoft (Bing) Url="http://www.bing.com/search?q={searchTer ... DF&PC=AV01"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} @ieframe.dll,-12512 Url="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Jirka\AppData\Roaming\Opera Software\Opera Stable\Web Data was reset successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1902485B-CE75-42C1-BA2D-57E660793D9A} deleted successfully
HKEY_USERS\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} deleted successfully
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0DACC63-037F-46EE-AC02-E4C7B0FBFEB4} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Empty IE Cache ======================

C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\temp\acro_rd_dir\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Jirka\AppData\Local\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Jirka\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=1428 folders=126 327989386 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Jirka\AppData\Local\temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Jirka\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Jirka\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ehmsdri.log" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\ehRecvr.log" not found

==== EOF on ne 23.11.2014 at 9:48:17,30 ======================

Dotaz: To, že se v logu objevuje "Chrome" znamená, že mám nainstalován prohlížeč, který jsem nikdy nechtěl?
MS Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika), Genuine Intel CPU2140@ 1.60GHz, 2.00GB RAM , NVIDIA GeForce 9400 GT

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#4 Příspěvek od vyosek »

:arrow: Ano, chrome by mel byt nainstalovan

:arrow: Poprosim o FRST http://forum.viry.cz/viewtopic.php?f=13&t=133100
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hooker
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 29 úno 2008 02:26
Bydliště: Čáslav

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#5 Příspěvek od Hooker »

Addition.rar
(4.8 KiB) Staženo 59 x
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-11-2014
Ran by Jirka (administrator) on JIRKA-PC on 23-11-2014 18:38:55
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 9
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files\CDBurnerXP\NMSAccessU.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe
() C:\Windows\System32\PnkBstrA.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
() C:\Windows\System32\atwtusb.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
() C:\Windows\System32\atwtusb.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Windows\System32\WTMKM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(RealNetworks, Inc.) C:\Program Files\real\realplayer\Update\realsched.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\ehome\ehsched.exe
(Microsoft Corporation) C:\Windows\ehome\ehrecvr.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(RealNetworks, Inc.) C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MacrokeyManager] => C:\Windows\system32\WTMKM.exe [7144448 2011-06-01] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-21] (AVAST Software)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [TkBellExe] => C:\Program Files\real\realplayer\update\realsched.exe [295512 2014-09-22] (RealNetworks, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6965792 2009-03-12] (Realtek Semiconductor)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [UIWatcher] => C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe [3509080 2010-02-09] (ashampoo GmbH & Co. KG)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
GroupPolicyUsers\S-1-5-21-3770246164-1455068142-2756262975-1002\User: Group Policy restriction detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.centrum.cz/
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTer ... DF&PC=AV01
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0045-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138

FireFox:
========
FF ProfilePath: C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll No File
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 -> c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Google™ Translator - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\Extensions\jid1-dgnIBwQga0SIBw@jetpack.xpi [2014-11-21]
FF Extension: Linkification - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\Extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}.xpi [2014-03-10]
FF Extension: BugMeNot Plugin - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\Extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}.xpi [2014-03-10]
FF Extension: Adblock Plus - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-03-13]
FF Extension: Open With Photoshop - C:\Users\Jirka\AppData\Roaming\Mozilla\Firefox\Profiles\760uro21.default-1394402520808\Extensions\{f3f219f9-cbce-467e-b8fe-6e076d29665c}.xpi [2014-07-09]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-03-21]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-18]
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-09-09]
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found]
FF Extension: No Name - {DF153AFF-6948-45d7-AC98-4FC4AF8A08E2} [Not Found]

Chrome:
=======
CHR Profile: C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-05]
CHR Extension: (Google Drive) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2012-11-07]
CHR Extension: (YouTube) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-11-07]
CHR Extension: (Google Search) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-11-07]
CHR Extension: (RealDownloader) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-07-05]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-11-07]
CHR Extension: (Gmail) - C:\Users\Jirka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-11-07]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-21]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-08-14]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-21] (AVAST Software)
R2 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [217088 2007-06-04] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2007-01-19] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
R2 NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2008-10-20] ()
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 OMSI download service; C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [90112 2009-04-30] () [File not signed]
S2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2011-11-05] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 WTService; C:\Windows\system32\atwtusb.exe [871936 2011-04-27] () [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 3xHybrid; C:\Windows\System32\DRIVERS\3xHybrid.sys [674048 2007-04-20] (Philips Semiconductors GmbH)
R3 ASUSVRC; C:\Windows\System32\DRIVERS\AsusVRC.sys [18432 2007-01-29] (ASUSTeK COMPUTER INC.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-11-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-11-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55240 2014-11-21] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-11-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-21] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57928 2014-11-21] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2014-11-21] ()
R1 EIO; C:\Windows\system32\drivers\EIO.sys [12288 2006-06-14] (ASUSTeK Computer Inc.) [File not signed]
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-09-23] (LogMeIn, Inc.)
R3 ip100Avista; C:\Windows\System32\DRIVERS\ipfnd51.sys [31232 2010-11-23] (IC Plus Corp. )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 moufiltr; C:\Windows\System32\DRIVERS\moufiltr.sys [6144 2009-03-08] (Windows (R) Codename Longhorn DDK provider)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
S3 s0016bus; C:\Windows\System32\DRIVERS\s0016bus.sys [89256 2008-05-16] (MCCI Corporation)
S3 s0016mdfl; C:\Windows\System32\DRIVERS\s0016mdfl.sys [15016 2008-05-16] (MCCI Corporation)
S3 s0016mdm; C:\Windows\System32\DRIVERS\s0016mdm.sys [120744 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\DRIVERS\s0016mgmt.sys [114216 2008-05-16] (MCCI Corporation)
S3 s0016nd5; C:\Windows\System32\DRIVERS\s0016nd5.sys [25512 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\DRIVERS\s0016obex.sys [110632 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\DRIVERS\s0016unic.sys [115752 2008-05-16] (MCCI Corporation)
S3 se3ebus; C:\Windows\System32\DRIVERS\se3ebus.sys [83080 2007-04-10] (MCCI Corporation)
S3 se3emdfl; C:\Windows\System32\DRIVERS\se3emdfl.sys [15112 2007-04-10] (MCCI Corporation)
S3 se3emdm; C:\Windows\System32\DRIVERS\se3emdm.sys [108552 2007-04-10] (MCCI Corporation)
S3 se3emgmt; C:\Windows\System32\DRIVERS\se3emgmt.sys [100360 2007-04-10] (MCCI Corporation)
S3 se3eobex; C:\Windows\System32\DRIVERS\se3eobex.sys [98568 2007-04-10] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-05-10] () [File not signed]
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2011-04-27] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [20864 2011-04-27] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [25216 2011-04-27] (LG Electronics Inc.)
R3 vhidmini; C:\Windows\System32\DRIVERS\walvhid.sys [6144 2009-08-20] (Windows (R) Win 7 DDK provider)
U3 a9r9iopu; C:\Windows\system32\Drivers\a9r9iopu.sys [0 ] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtport.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbus.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmodem.sys [X]
S3 NTACCESS; \??\E:\NTACCESS.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SetupNTGLM7X; \??\E:\NTGLM7X.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-23 18:38 - 2014-11-23 18:39 - 00022202 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-23 18:38 - 2014-11-23 18:39 - 00000000 ____D () C:\FRST
2014-11-23 18:34 - 2014-11-23 18:34 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-23 18:33 - 2014-11-23 18:33 - 01110016 _____ (Farbar) C:\Users\Jirka\Desktop\FRST.exe
2014-11-23 18:32 - 2014-11-23 18:36 - 00000000 ____D () C:\Users\Jirka\Desktop\FRSIT
2014-11-23 09:45 - 2014-11-23 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-23 09:19 - 2014-11-23 09:48 - 00019354 _____ () C:\zoek-results.log
2014-11-23 09:18 - 2014-11-23 09:41 - 00000000 ____D () C:\zoek_backup
2014-11-23 09:17 - 2014-11-23 09:17 - 01294848 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-23 02:19 - 2014-11-23 02:19 - 00003328 _____ () C:\Users\Jirka\Desktop\mbam.txt
2014-11-23 02:17 - 2014-11-23 03:35 - 00003408 _____ () C:\Users\Jirka\Desktop\anti-malvare.txt
2014-11-22 23:56 - 2014-11-22 23:56 - 00000000 ____D () C:\rsit
2014-11-22 22:58 - 2014-11-22 22:58 - 00000000 ____D () C:\ProgramData\HP Product Assistant
2014-11-22 22:50 - 2014-11-22 22:50 - 00009822 _____ () C:\Users\Jirka\Desktop\AdwCleaner[S1].txt
2014-11-22 22:30 - 2014-11-22 22:30 - 00321848 _____ (Malwarebytes Corporation) C:\Users\Jirka\Desktop\mbam-clean-2.1.1.1001.exe
2014-11-22 21:48 - 2014-11-22 21:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-22 21:48 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-22 21:48 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-22 21:17 - 2014-11-22 22:59 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\HpUpdate
2014-11-22 00:09 - 2014-11-22 00:09 - 02140160 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.101.exe
2014-11-21 20:54 - 2014-11-21 20:55 - 00002532 _____ () C:\Users\Jirka\Documents\cc_20141121_205449.reg
2014-11-21 19:59 - 2014-11-21 19:59 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2014-11-21 19:41 - 2014-11-21 20:13 - 00146090 _____ () C:\Windows\hpoins12.dat
2014-11-21 14:26 - 2014-11-21 14:26 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\HP
2014-11-21 10:46 - 2014-11-22 23:02 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-11-21 10:18 - 2014-11-22 21:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-11-21 10:18 - 2014-11-21 10:18 - 00000000 ____D () C:\ProgramData\HPSSUPPLY
2014-11-21 10:15 - 2014-11-21 10:15 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2014-11-21 10:14 - 2006-12-15 17:04 - 00258048 _____ (Hewlett-Packard) C:\Windows\system32\hpzids01.dll
2014-11-21 10:04 - 2014-11-21 20:13 - 00005064 _____ () C:\ProgramData\hpzinstall.log
2014-11-21 10:03 - 2014-11-21 20:00 - 00000000 ____D () C:\ProgramData\HP
2014-11-21 09:50 - 2014-11-21 09:50 - 00002936 _____ () C:\Users\Jirka\Documents\cc_20141121_095034.reg
2014-11-21 08:17 - 2014-11-21 10:22 - 00000000 ____D () C:\Program Files\Common Files\HP
2014-11-21 07:52 - 2014-11-21 07:52 - 00291352 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-21 07:52 - 2014-11-21 07:52 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-20 22:55 - 2014-11-20 22:55 - 00022180 _____ () C:\Users\Jirka\Documents\cc_20141120_225505.reg
2014-11-20 20:49 - 2014-11-21 19:54 - 00052024 _____ () C:\Windows\DPINST.LOG
2014-11-20 10:03 - 2014-11-20 10:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-11-20 10:02 - 2014-11-20 10:02 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-11-20 09:40 - 2014-10-24 02:03 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-20 05:13 - 2014-11-20 05:13 - 01500304 _____ () C:\Users\Jirka\Downloads\help_sk.chm
2014-11-16 22:19 - 2014-11-16 22:19 - 00006548 _____ () C:\Users\Jirka\Documents\cc_20141116_221910.reg
2014-11-14 08:37 - 2014-11-14 08:37 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-14 08:21 - 2014-11-23 00:54 - 00000000 ____D () C:\Users\Jirka\Desktop\BACKUP
2014-11-14 07:18 - 2014-11-14 07:18 - 00465088 _____ (Mozilla, Netscape) C:\Users\Jirka\Downloads\xpcom.dll
2014-11-13 18:55 - 2014-11-13 18:56 - 00133850 _____ () C:\Users\Jirka\Documents\cc_20141113_185515.reg
2014-11-13 18:29 - 2014-06-15 23:18 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-11-13 18:29 - 2014-06-13 19:22 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-11-13 18:29 - 2014-06-13 19:22 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-11-13 18:27 - 2014-10-10 02:01 - 00449536 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-13 18:27 - 2014-10-10 02:00 - 01259008 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-13 18:27 - 2014-10-10 02:00 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-13 18:27 - 2014-10-10 00:22 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-13 18:25 - 2014-08-27 01:55 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-13 18:25 - 2014-08-27 01:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-13 18:24 - 2014-09-19 01:50 - 00278528 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-13 18:23 - 2014-10-24 02:04 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-13 18:23 - 2014-08-12 03:25 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-13 18:21 - 2014-10-18 02:08 - 00564224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-13 18:21 - 2014-10-03 02:18 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-13 18:21 - 2014-10-03 02:17 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-13 18:21 - 2014-10-03 02:17 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-13 18:21 - 2014-10-03 02:17 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-13 18:21 - 2014-09-05 00:27 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2014-11-13 18:11 - 2014-10-13 00:34 - 02054656 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-13 18:05 - 2014-10-27 19:59 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-13 18:05 - 2014-10-27 19:57 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-13 18:05 - 2014-10-27 19:56 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-11-13 18:05 - 2014-10-27 19:56 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-13 18:05 - 2014-10-27 19:56 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-13 18:05 - 2014-10-27 19:55 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-13 18:05 - 2014-10-27 19:55 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-11-13 18:05 - 2014-10-27 19:55 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-11-13 18:05 - 2014-10-27 19:55 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-11-13 18:04 - 2014-10-27 20:10 - 12366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-13 18:04 - 2014-10-27 20:05 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-13 18:04 - 2014-10-27 20:02 - 09739776 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-13 18:04 - 2014-10-27 19:59 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-13 18:04 - 2014-10-27 19:58 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-13 18:04 - 2014-10-27 19:57 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-11-13 18:04 - 2014-10-27 19:56 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-13 18:04 - 2014-10-27 19:56 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-13 18:04 - 2014-10-27 19:55 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-13 18:04 - 2014-10-27 19:55 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-13 18:04 - 2014-10-27 19:55 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-13 18:04 - 2014-10-27 19:54 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-13 10:09 - 2014-11-13 10:09 - 00000000 ____D () C:\Program Files\Common Files\Java(75)
2014-11-12 19:50 - 2014-11-12 19:51 - 00000000 ____D () C:\Program Files\QuickTime(119)
2014-11-09 10:10 - 2014-11-12 07:05 - 00004397 _____ () C:\Users\Jirka\Desktop\youtube.txt
2014-11-06 11:31 - 2014-11-12 21:48 - 00003224 _____ () C:\Users\Jirka\Desktop\jirka.txt
2014-10-28 22:44 - 2014-10-28 22:44 - 00121623 _____ () C:\Users\Jirka\Desktop\Silent Runners.zip

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-11-23 17:47 - 2009-03-25 07:39 - 01743366 _____ () C:\Windows\WindowsUpdate.log
2014-11-23 17:46 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-23 17:46 - 2006-11-02 13:47 - 00004176 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-23 10:44 - 2013-03-07 14:00 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-23 09:49 - 2006-11-02 13:37 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-11-23 09:47 - 2014-04-01 08:50 - 00015818 _____ () C:\Windows\PFRO.log
2014-11-23 09:47 - 2013-07-21 10:01 - 00000008 __RSH () C:\Users\Jirka\ntuser.pol
2014-11-23 09:47 - 2009-03-21 22:36 - 00000000 ____D () C:\Users\Jirka
2014-11-23 09:47 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-23 09:47 - 2006-11-02 11:23 - 00000249 _____ () C:\Windows\win.ini
2014-11-23 09:46 - 2006-11-02 14:01 - 00032546 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-23 09:40 - 2006-11-02 12:18 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-11-23 09:05 - 2013-11-22 02:36 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-11-23 06:20 - 2010-03-16 22:01 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-11-23 03:21 - 2014-03-25 02:15 - 00003913 _____ () C:\Users\Jirka\Desktop\reged.txt
2014-11-23 02:25 - 2009-08-16 21:14 - 00000000 ____D () C:\Users\Jirka\Desktop\CLEAN
2014-11-23 02:23 - 2011-11-16 08:28 - 00000000 ____D () C:\Users\Jirka\Desktop\Zástupci-PDF
2014-11-23 01:49 - 2010-02-27 22:44 - 00000000 ___RD () C:\Users\Jirka\Desktop\ 
2014-11-23 00:07 - 2009-06-06 21:54 - 00000000 ____D () C:\Program Files\Trend Micro
2014-11-22 22:44 - 2013-11-11 01:16 - 00000000 ____D () C:\AdwCleaner
2014-11-22 21:48 - 2010-03-16 22:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-22 10:28 - 2009-04-06 22:56 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Image Zone Express
2014-11-22 09:51 - 2011-09-18 19:30 - 00787800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-21 22:37 - 2010-08-15 11:08 - 00010752 _____ () C:\Users\Jirka\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-11-21 21:59 - 2014-09-08 18:42 - 00000000 ____D () C:\Users\Jirka\Desktop\TWAIN
2014-11-21 21:47 - 2010-02-09 16:32 - 00000000 ___RD () C:\Users\Jirka\Desktop\HP
2014-11-21 21:12 - 2011-04-08 19:43 - 00000000 ____D () C:\Program Files\Google
2014-11-21 19:59 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\twain_32
2014-11-21 19:36 - 2009-04-06 22:56 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Printer Info Cache
2014-11-21 10:22 - 2009-03-23 01:39 - 00000000 ____D () C:\Program Files\HP
2014-11-21 09:35 - 2009-03-22 21:42 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-11-21 08:02 - 2006-11-02 11:33 - 01560044 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-21 07:52 - 2014-04-24 22:22 - 00024184 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-21 07:52 - 2013-03-07 09:49 - 00206248 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-21 07:52 - 2013-03-07 09:49 - 00049944 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-21 07:52 - 2011-09-18 19:30 - 00423784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-11-21 07:52 - 2011-09-18 19:30 - 00070384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-11-21 07:52 - 2011-09-18 19:30 - 00057928 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2014-11-21 07:52 - 2011-09-18 19:30 - 00055240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswrdr.sys
2014-11-20 22:53 - 2009-03-25 17:51 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Media Player Classic
2014-11-20 10:03 - 2014-02-27 00:13 - 00000000 ____D () C:\Program Files\QuickTime
2014-11-16 22:22 - 2009-03-22 11:29 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-16 20:38 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-11-16 16:57 - 2012-04-25 13:36 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-14 22:42 - 2013-05-24 13:40 - 00000000 ____D () C:\Users\Jirka\Documents\FIREFOX
2014-11-14 08:37 - 2011-11-11 06:15 - 00000824 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-14 06:50 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\rescache
2014-11-13 21:36 - 2006-11-02 13:47 - 00259448 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-13 21:23 - 2012-04-14 07:14 - 00000000 ____D () C:\Program Files\Opera
2014-11-13 19:44 - 2013-03-07 14:00 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-11-13 19:44 - 2011-05-25 21:10 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-11-13 18:17 - 2013-07-20 19:50 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 17:48 - 2009-03-21 22:37 - 00055864 _____ () C:\Users\Jirka\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-13 17:43 - 2006-11-02 11:22 - 52428800 _____ () C:\Windows\system32\config\software_previous
2014-11-13 17:43 - 2006-11-02 11:22 - 42729472 _____ () C:\Windows\system32\config\components_previous
2014-11-13 17:43 - 2006-11-02 11:22 - 33030144 _____ () C:\Windows\system32\config\system_previous
2014-11-13 17:43 - 2006-11-02 11:22 - 04718592 _____ () C:\Windows\system32\config\default_previous
2014-11-13 17:43 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2014-11-13 17:43 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2014-11-13 17:41 - 2014-01-26 21:05 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\vlc
2014-11-13 17:41 - 2014-01-26 21:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-11-13 17:41 - 2013-11-17 13:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-11-13 17:41 - 2013-11-17 13:27 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-11-13 17:41 - 2013-11-11 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX
2014-11-13 17:41 - 2013-02-21 05:28 - 00000000 ___RD () C:\Users\Jirka\Documents\Notes
2014-11-13 17:41 - 2013-01-10 08:10 - 00000000 ____D () C:\ProgramData\Tablet
2014-11-13 17:41 - 2012-09-22 16:30 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\uTorrent
2014-11-13 17:41 - 2010-07-19 15:33 - 00000000 ____D () C:\ProgramData\DivX
2014-11-13 17:41 - 2010-06-18 20:40 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\BITS
2014-11-13 17:41 - 2010-06-15 19:19 - 00000000 ____D () C:\Users\Jirka\Desktop\PETR-HRY
2014-11-13 17:41 - 2009-08-08 11:52 - 00000000 ____D () C:\Users\Jirka\Documents\PDF
2014-11-13 17:41 - 2009-07-28 19:47 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Skype
2014-11-13 17:41 - 2009-07-25 14:20 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\x2xsoft
2014-11-13 17:41 - 2009-07-18 14:35 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defraggler
2014-11-13 17:41 - 2009-07-02 08:58 - 00000000 ____D () C:\Program Files\DivX
2014-11-13 17:41 - 2009-06-15 12:38 - 00000000 ___RD () C:\Users\Jirka\Desktop\Multimed
2014-11-13 17:41 - 2009-05-17 08:14 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recuva
2014-11-13 17:41 - 2009-03-26 21:50 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-11-13 17:41 - 2009-03-22 11:29 - 00000000 ____D () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-13 17:41 - 2009-03-21 22:36 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-13 17:41 - 2009-03-21 22:36 - 00000000 ___RD () C:\Users\Jirka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-13 17:41 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool
2014-11-13 17:40 - 2009-05-14 10:17 - 00000000 ____D () C:\ProgramData\Real
2014-11-13 17:40 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration
2014-11-13 16:44 - 2010-03-16 22:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-11-13 16:44 - 2009-09-30 03:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird
2014-11-13 16:44 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-11-13 10:08 - 2014-02-18 09:19 - 00000000 ____D () C:\ProgramData\Oracle
2014-11-04 14:30 - 2009-10-03 00:45 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-01 12:31 - 2014-10-21 17:51 - 00000000 ____D () C:\Users\Jirka\AppData\Local\Adobe
2014-11-01 12:31 - 2010-04-24 20:36 - 00000000 ____D () C:\Program Files\Common Files\Adobe AIR
2014-10-31 23:25 - 2006-11-02 11:24 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-10-29 21:32 - 2014-01-04 14:25 - 00000000 ____D () C:\Users\Jirka\Desktop\RINGTONE

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================


==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Jirka\Desktop" je 785 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe"="C:\\Program Files\\FlashGet Network\\FlashGet 3\\FlashGet3.exe:*:Enabled:Flashget3"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000


==================== End Of Log ==============================
MS Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika), Genuine Intel CPU2140@ 1.60GHz, 2.00GB RAM , NVIDIA GeForce 9400 GT

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#6 Příspěvek od vyosek »

:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    
    HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
    HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
    HKLM\...\Run: [TkBellExe] => C:\Program Files\real\realplayer\update\realsched.exe [295512 2014-09-22] (RealNetworks, Inc.)
    HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
    HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
    HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
    HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
    HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
    HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [UIWatcher] => C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe [3509080 2010-02-09] (ashampoo GmbH & Co. KG)
    KU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
    HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)
    GroupPolicyUsers\S-1-5-21-3770246164-1455068142-2756262975-1002\User: Group Policy restriction detected <======= ATTENTION
    
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
    SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
    
    FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found]
    FF Extension: No Name - {DF153AFF-6948-45d7-AC98-4FC4AF8A08E2} [Not Found]
    
    S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
    S3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [X]
    S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
    S3 LgBttPort; system32\DRIVERS\lgbtport.sys [X]
    S3 lgbusenum; system32\DRIVERS\lgbtbus.sys [X]
    S3 LGVMODEM; system32\DRIVERS\lgvmodem.sys [X]
    S3 NTACCESS; \??\E:\NTACCESS.sys [X]
    S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
    S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
    S3 SetupNTGLM7X; \??\E:\NTGLM7X.sys [X]
    
    2014-11-23 18:38 - 2014-11-23 18:39 - 00022202 _____ () C:\Users\Jirka\Desktop\FRST.txt
    2014-11-23 18:34 - 2014-11-23 18:34 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
    2014-11-23 09:45 - 2014-11-23 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
    2014-11-23 09:19 - 2014-11-23 09:48 - 00019354 _____ () C:\zoek-results.log
    2014-11-23 09:18 - 2014-11-23 09:41 - 00000000 ____D () C:\zoek_backup
    2014-11-23 09:17 - 2014-11-23 09:17 - 01294848 _____ () C:\Users\Jirka\Desktop\zoek.exe
    2014-11-23 02:19 - 2014-11-23 02:19 - 00003328 _____ () C:\Users\Jirka\Desktop\mbam.txt
    2014-11-23 02:17 - 2014-11-23 03:35 - 00003408 _____ () C:\Users\Jirka\Desktop\anti-malvare.txt
    2014-11-22 23:56 - 2014-11-22 23:56 - 00000000 ____D () C:\rsit
    2014-11-22 22:50 - 2014-11-22 22:50 - 00009822 _____ () C:\Users\Jirka\Desktop\AdwCleaner[S1].txt
    2014-11-22 22:30 - 2014-11-22 22:30 - 00321848 _____ (Malwarebytes Corporation) C:\Users\Jirka\Desktop\mbam-clean-2.1.1.1001.exe
    2014-11-22 21:48 - 2014-11-22 21:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
    2014-11-22 21:48 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
    2014-11-22 21:48 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
    2014-11-22 00:09 - 2014-11-22 00:09 - 02140160 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.101.exe
    2014-11-21 20:54 - 2014-11-21 20:55 - 00002532 _____ () C:\Users\Jirka\Documents\cc_20141121_205449.reg
    2014-11-22 22:44 - 2013-11-11 01:16 - 00000000 ____D () C:\AdwCleaner
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hooker
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 29 úno 2008 02:26
Bydliště: Čáslav

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#7 Příspěvek od Hooker »

Tak jenom doufám, že je to ten správný log. Ihned po spuštění FF došlo k zamrznutí prohlížeče s oznámením, že skript nereaguje, srovnalo se to samo.

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 23-11-2014
Ran by Jirka at 2014-11-23 20:59:31 Run:1
Running from C:\Users\Jirka\Desktop
Loaded Profile: Jirka (Available profiles: Jirka)
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Start
CloseProcesses:

HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [TkBellExe] => C:\Program Files\real\realplayer\update\realsched.exe [295512 2014-09-22] (RealNetworks, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49152 2006-12-10] (Hewlett-Packard Co.)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [UIWatcher] => C:\Program Files\Ashampoo\Ashampoo UnInstaller 3\UIWatcher.exe [3509080 2010-02-09] (ashampoo GmbH & Co. KG)
KU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation)
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)
GroupPolicyUsers\S-1-5-21-3770246164-1455068142-2756262975-1002\User: Group Policy restriction detected <======= ATTENTION

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-3770246164-1455068142-2756262975-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}

FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found]
FF Extension: No Name - {DF153AFF-6948-45d7-AC98-4FC4AF8A08E2} [Not Found]

S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 GMSIPCI; \??\E:\INSTALL\GMSIPCI.SYS [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtport.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbus.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmodem.sys [X]
S3 NTACCESS; \??\E:\NTACCESS.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SetupNTGLM7X; \??\E:\NTGLM7X.sys [X]

2014-11-23 18:38 - 2014-11-23 18:39 - 00022202 _____ () C:\Users\Jirka\Desktop\FRST.txt
2014-11-23 18:34 - 2014-11-23 18:34 - 00112640 _____ (forum.viry.cz) C:\Users\Jirka\Desktop\FRSTLauncher.exe
2014-11-23 09:45 - 2014-11-23 09:18 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-11-23 09:19 - 2014-11-23 09:48 - 00019354 _____ () C:\zoek-results.log
2014-11-23 09:18 - 2014-11-23 09:41 - 00000000 ____D () C:\zoek_backup
2014-11-23 09:17 - 2014-11-23 09:17 - 01294848 _____ () C:\Users\Jirka\Desktop\zoek.exe
2014-11-23 02:19 - 2014-11-23 02:19 - 00003328 _____ () C:\Users\Jirka\Desktop\mbam.txt
2014-11-23 02:17 - 2014-11-23 03:35 - 00003408 _____ () C:\Users\Jirka\Desktop\anti-malvare.txt
2014-11-22 23:56 - 2014-11-22 23:56 - 00000000 ____D () C:\rsit
2014-11-22 22:50 - 2014-11-22 22:50 - 00009822 _____ () C:\Users\Jirka\Desktop\AdwCleaner[S1].txt
2014-11-22 22:30 - 2014-11-22 22:30 - 00321848 _____ (Malwarebytes Corporation) C:\Users\Jirka\Desktop\mbam-clean-2.1.1.1001.exe
2014-11-22 21:48 - 2014-11-22 21:48 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-22 21:48 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-22 21:48 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-22 00:09 - 2014-11-22 00:09 - 02140160 _____ () C:\Users\Jirka\Desktop\adwcleaner_4.101.exe
2014-11-21 20:54 - 2014-11-21 20:55 - 00002532 _____ () C:\Users\Jirka\Documents\cc_20141121_205449.reg
2014-11-22 22:44 - 2013-11-11 01:16 - 00000000 ____D () C:\AdwCleaner

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\NvBackend => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\TkBellExe => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DivXMediaServer => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Run\\UIWatcher => value deleted successfully.
KU\S-1-5-21-3770246164-1455068142-2756262975-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-19] (Microsoft Corporation) => Error: No automatic fix found for this entry.
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value deleted successfully.
C:\Windows\system32\GroupPolicyUsers\S-1-5-21-3770246164-1455068142-2756262975-1002\User => Moved successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKU\S-1-5-21-3770246164-1455068142-2756262975-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\ToolbarSearchProviderProgress => value deleted successfully.
FF Extension: No Name - {20a82645-c095-46ed-80e3-08825760534b} [Not Found] => not found.
FF Extension: No Name - {DF153AFF-6948-45d7-AC98-4FC4AF8A08E2} [Not Found] => not found.
blbdrive => Service deleted successfully.
catchme => Service deleted successfully.
GMSIPCI => Service deleted successfully.
IpInIp => Service deleted successfully.
LgBttPort => Service deleted successfully.
lgbusenum => Service deleted successfully.
LGVMODEM => Service deleted successfully.
NTACCESS => Service deleted successfully.
NwlnkFlt => Service deleted successfully.
NwlnkFwd => Service deleted successfully.
SetupNTGLM7X => Service deleted successfully.
C:\Users\Jirka\Desktop\FRST.txt => Moved successfully.
C:\Users\Jirka\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\Jirka\Desktop\zoek.exe => Moved successfully.
C:\Users\Jirka\Desktop\mbam.txt => Moved successfully.
C:\Users\Jirka\Desktop\anti-malvare.txt => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\Jirka\Desktop\AdwCleaner[S1].txt => Moved successfully.
C:\Users\Jirka\Desktop\mbam-clean-2.1.1.1001.exe => Moved successfully.
C:\Program Files\Malwarebytes Anti-Malware => Moved successfully.
C:\Windows\system32\Drivers\mbamchameleon.sys => Moved successfully.
C:\Windows\system32\Drivers\mwac.sys => Moved successfully.
C:\Users\Jirka\Desktop\adwcleaner_4.101.exe => Moved successfully.
C:\Users\Jirka\Documents\cc_20141121_205449.reg => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 359.2 MB temporary data.


The system needed a reboot.

==== End of Fixlog ====
MS Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika), Genuine Intel CPU2140@ 1.60GHz, 2.00GB RAM , NVIDIA GeForce 9400 GT

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#8 Příspěvek od vyosek »

:arrow: V poradku

Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remote disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Hooker
Návštěvník
Návštěvník
Příspěvky: 109
Registrován: 29 úno 2008 02:26
Bydliště: Čáslav

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#9 Příspěvek od Hooker »

Tak úklid vykonán, vypadá to dobře, v noci a zítra pc prověřím. Díky za Váš čas a ochotu.
MS Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika), Genuine Intel CPU2140@ 1.60GHz, 2.00GB RAM , NVIDIA GeForce 9400 GT

Uživatelský avatar
vyosek
VIP
VIP
Příspěvky: 56373
Registrován: 07 lis 2006 15:24
Bydliště: Šalingrad - Brno

Re: Nové, nechtěné programy v compu, FF- zaplněná op. paměť

#10 Příspěvek od vyosek »

OK, otestujte a dejte vedet...
"Kdo víno má a nepije,kdo hrozny má a nejí je, kdo ženu má a nelíbá, kdo zábavě se vyhýbá, na toho vemte bič a hůl, to není člověk, to je vůl."
Člen Obrázek od 1. února 2011.

Odpovědět