
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
spomaleny pocitac, eset odstránil viacere infiltracie
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
spomaleny pocitac, eset odstránil viacere infiltracie
Dobrý deň, prosím o kontrolu logu notebook je totálne pomaly a zasekáva sa aj na niekolko minút aj keď je procesor nezaťaženy (do 10%). Kontrola esetom - preukazala infiltracie WIN32/BitCoinMiner.BV; .BY a Win32/InstallCore.RO.
Ani po odstránení infikovaných súborov sa situacia nezlešila, voprad ďakujem
Prikladám LOG:
Logfile of random's system information tool 1.10 (written by random/random)
Run by q at 2014-12-09 21:10:09
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 51 GB (49%) free of 105 GB
Total RAM: 1982 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:10:21, on 9. 12. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17420)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\System Explorer\SystemExplorer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files\trend micro\q.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [SystemExplorerAutoStart] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: LibreOffice 4.3.lnk = C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe
O4 - Startup: Miranda64 - odkaz.lnk = D:\portables\PortableApps\miranda\Miranda64.exe
O4 - Startup: PureText - odkaz.lnk = D:\portables\PortableApps\puretext\PureText.exe
O4 - Startup: Start - odkaz.lnk = D:\portables\Start.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{B06296C6-4AEA-4484-B8F1-455E2557F8AA}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DraftSight API Service - Dassault Systemes - C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10129 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11514 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe" C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\LibreOffice 4\program\soffice.exe" --quickstart
"C:\Program Files (x86)\LibreOffice 4\program\soffice.exe" "--quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\LibreOffice 4\\program"
"D:\portables\PortableApps\puretext\PureText.exe"
"D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
"C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe"
"D:\portables\PortableApps\miranda\Miranda64.exe" /restart
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Program Files (x86)\Notepad++\notepad++.exe" "C:\rsit\log.txt"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\q\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Ani po odstránení infikovaných súborov sa situacia nezlešila, voprad ďakujem
Prikladám LOG:
Logfile of random's system information tool 1.10 (written by random/random)
Run by q at 2014-12-09 21:10:09
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 51 GB (49%) free of 105 GB
Total RAM: 1982 MB (38% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:10:21, on 9. 12. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17420)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\System Explorer\SystemExplorer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files\trend micro\q.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
O4 - HKLM\..\Run: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKLM\..\Run: [SystemExplorerAutoStart] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [ShowBatteryBar] "C:\Program Files\BatteryBar\ShowBatteryBar.exe" show
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: LibreOffice 4.3.lnk = C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe
O4 - Startup: Miranda64 - odkaz.lnk = D:\portables\PortableApps\miranda\Miranda64.exe
O4 - Startup: PureText - odkaz.lnk = D:\portables\PortableApps\puretext\PureText.exe
O4 - Startup: Start - odkaz.lnk = D:\portables\Start.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O9 - Extra 'Tools' menuitem: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-247 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{B06296C6-4AEA-4484-B8F1-455E2557F8AA}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Atheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: Bluetooth Device Manager - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
O23 - Service: Bluetooth Media Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\audiosrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files\Motorola\Bluetooth\obexsrv.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: DraftSight API Service - Dassault Systemes - C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FLEXnet Licensing Service 64 - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: HP Power Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
O23 - Service: hpHotkeyMonitor - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10129 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11514 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
"C:\Program Files\IDT\WDM\STacSV64.exe"
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\IDT\WDM\AESTSr64.exe"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe"
"C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe" C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
"C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Motorola\Bluetooth\obexsrv.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe"
"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe"
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\LibreOffice 4\program\soffice.exe" --quickstart
"C:\Program Files (x86)\LibreOffice 4\program\soffice.exe" "--quickstart" "-env:OOO_CWD=2C:\\Program Files (x86)\\LibreOffice 4\\program"
"D:\portables\PortableApps\puretext\PureText.exe"
"D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" /start
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
"C:\Program Files (x86)\System Explorer\SystemExplorer.exe" /TRAY
"C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe"
"D:\portables\PortableApps\miranda\Miranda64.exe" /restart
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\totalcmd\TOTALCMD64.EXE"
"C:\Program Files (x86)\Notepad++\notepad++.exe" "C:\rsit\log.txt"
"C:\Windows\system32\wuauclt.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Users\q\Downloads\RSITx64.exe"
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Re: spomaleny pocitac, eset odstránil viacere infiltracie
pripajam log z FFRST:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-12-2014
Ran by q (administrator) on KNI4 on 09-12-2014 21:45:32
Running from C:\Users\q\Desktop
Loaded Profile: q (Available profiles: q)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Dassault Systèmes) C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Flexera Software, Inc.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
(http://www.SteveMiller.net) D:\portables\PortableApps\puretext\PureText.exe
(PortableApps.com) D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(Miranda NG Team) D:\portables\PortableApps\miranda\Miranda64.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2918656 2011-01-12] (ESET)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [323128 2011-07-06] (Hewlett-Packard Company)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SystemExplorerAutoStart] => C:\Program Files (x86)\System Explorer\SystemExplorer.exe [3830632 2014-06-24] (Mister Group)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X]
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [ShowBatteryBar] => C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2014-09-19] ()
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Policies\system: [Wallpaper] c:\Windows\Web\Wallpaper\Characters\plocha.jpg
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Policies\system: [WallpaperStyle] 0
IFEO\taskmgr.exe: [Debugger] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe"
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.3.lnk
ShortcutTarget: LibreOffice 4.3.lnk -> C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe ()
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk
ShortcutTarget: Miranda64 - odkaz.lnk -> D:\portables\PortableApps\miranda\Miranda64.exe (Miranda NG Team)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk
ShortcutTarget: PureText - odkaz.lnk -> D:\portables\PortableApps\puretext\PureText.exe (http://www.SteveMiller.net)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start - odkaz.lnk
ShortcutTarget: Start - odkaz.lnk -> D:\portables\Start.exe (PortableApps.com)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.10
Tcpip\..\Interfaces\{B06296C6-4AEA-4484-B8F1-455E2557F8AA}: [NameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/GoogleTalkPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/O1DPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=3 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=9 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10]
FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19]
FF Extension: Gmail panel - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2014-11-19]
FF Extension: gTranslate - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi [2014-11-19]
FF Extension: Adblock Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-10]
FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-12-16]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR StartMenuInternet: Google Chrome - C:\Users\test1\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [53920 2011-01-06] (Atheros Commnucations) [File not signed]
R2 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [123392 2014-03-14] (Dassault Systèmes) [File not signed]
S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [42360 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [810144 2011-01-12] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2011-12-16] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [1698360 2011-07-06] (Hewlett-Packard Company)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2014-04-25] (IDT, Inc.) [File not signed]
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-11-25] (Mister Group)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [38424 2010-10-18] (Google Inc)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [125296 2010-12-21] (ESET)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769304 2014-05-11] (http://www.ext2fsd.com)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
S3 GeneStor; C:\Windows\System32\DRIVERS\GeneStor.sys [58368 2014-05-17] (GenesysLogic)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-05-12] (Intel Corporation)
R3 mv2; C:\Windows\System32\DRIVERS\mv2.sys [12904 2012-02-17] (UVNC BVBA)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [328808 2010-10-28] (Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3073752 2014-04-25] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1863680 2012-03-30] (Sonix Co. Ltd.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512952 2014-04-25] (Sunplus)
S3 vserial; System32\DRIVERS\vserial.sys [X]
U3 wampapache; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-09 21:45 - 2014-12-09 21:46 - 00014678 _____ () C:\Users\q\Desktop\FRST.txt
2014-12-09 21:43 - 2014-12-09 21:44 - 02119680 _____ (Farbar) C:\Users\q\Desktop\FRST64.exe
2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
2014-12-09 21:29 - 2014-12-09 21:34 - 05937745 _____ () C:\Users\q\Downloads\MTK6582 MTK6589 MTK6592 ROOT.zip.part
2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit
2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe
2014-12-09 20:47 - 2014-12-09 20:47 - 00000056 _____ () C:\Windows\setupact.log
2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-09 20:46 - 2014-12-09 20:46 - 00005672 _____ () C:\Windows\PFRO.log
2014-12-08 18:37 - 2014-12-08 18:38 - 00009416 _____ () C:\Users\q\Downloads\services.m3u
2014-12-07 12:20 - 2014-12-07 12:20 - 00000000 ____D () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH
2014-12-06 23:57 - 2014-12-06 23:57 - 00000000 ____D () C:\Users\q\Downloads\code39
2014-12-06 23:56 - 2014-12-06 23:56 - 00002399 _____ () C:\Users\q\Downloads\code39.zip
2014-12-06 23:54 - 2014-12-06 23:54 - 00000000 ____D () C:\Users\q\Downloads\code_128
2014-12-06 23:53 - 2014-12-06 23:53 - 00002240 _____ () C:\Users\q\Downloads\code_128.zip
2014-12-06 23:39 - 2014-12-06 23:39 - 00000000 ____D () C:\Users\q\Downloads\free3of9
2014-12-06 23:38 - 2014-12-06 23:38 - 00005342 _____ () C:\Users\q\Downloads\free3of9.zip
2014-12-06 23:17 - 2014-12-07 00:22 - 00156154 _____ () C:\Users\q\Desktop\Backup_of_johndeere.cdr
2014-12-06 22:43 - 2014-12-06 22:43 - 00127053 _____ () C:\Users\q\Downloads\antigoni.zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(2).zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(1).zip
2014-12-06 22:11 - 2014-12-07 11:04 - 00156778 _____ () C:\Users\q\Desktop\johndeere.cdr
2014-12-06 22:10 - 2014-12-06 22:10 - 00000000 ____D () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com
2014-12-06 22:09 - 2014-12-06 22:10 - 00009029 _____ () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com.zip
2014-12-06 21:43 - 2014-12-06 21:43 - 00000000 ____D () C:\Users\q\Downloads\Media-Gothic
2014-12-06 21:42 - 2014-12-06 21:42 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic.zip
2014-12-06 21:11 - 2014-12-06 21:35 - 03330106 _____ () C:\Users\q\Desktop\IMG_0969.xcf
2014-12-06 19:51 - 2014-12-06 20:03 - 57897385 _____ () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH.zip
2014-12-01 22:08 - 2014-12-01 22:08 - 00711376 _____ () C:\Users\q\Downloads\oscamOSEmu_8933
2014-12-01 22:07 - 2014-12-01 22:07 - 00061800 _____ () C:\Users\q\Downloads\OSEmu
2014-12-01 22:05 - 2014-12-01 22:05 - 00164599 _____ () C:\Users\q\Downloads\OSEmu-1.02r-optimized-sh4-linux.zip
2014-12-01 22:03 - 2014-12-01 22:03 - 00171138 _____ () C:\Users\q\Downloads\OSEmu-1.02r-sh4-linux.zip
2014-12-01 21:43 - 2014-12-01 21:43 - 01235688 _____ () C:\Users\q\Downloads\oscam_emu.zip
2014-12-01 21:36 - 2014-12-01 21:38 - 00690803 _____ () C:\Users\q\Downloads\oscam-1.20-unstable_svn9812-OSEmu-1.02h-sh4-linux.zip
2014-12-01 21:20 - 2014-12-01 21:20 - 00474433 _____ () C:\Users\q\Downloads\oscam-svn10060-sh_4-webif-oscam-emu-patched.zip
2014-12-01 19:47 - 2014-12-01 19:47 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\q\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-30 18:41 - 2014-11-30 18:44 - 00000000 ____D () C:\Users\q\cr3
2014-11-30 07:57 - 2014-11-30 07:57 - 00000000 ____D () C:\Users\q\Documents\My Palettes
2014-11-30 07:12 - 2014-11-30 07:45 - 585322958 _____ () C:\Users\q\Downloads\CorelDRAWGSX6-v16.2.0.998-Portable.rar
2014-11-30 06:53 - 2014-11-30 06:54 - 00000000 ____D () C:\Windows\SysWOW64\spool
2014-11-28 21:15 - 2014-11-28 21:15 - 00002088 _____ () C:\Users\Public\Desktop\SDFormatter.lnk
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\Program Files (x86)\SDA
2014-11-28 20:55 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-28 20:53 - 2014-11-28 20:54 - 06286748 _____ () C:\Users\q\Downloads\SDFormatterv4.zip
2014-11-28 10:44 - 2014-11-28 10:45 - 06333290 _____ () C:\Users\q\Downloads\AmazonApps-release.apk
2014-11-21 16:54 - 2014-11-21 16:55 - 38662656 _____ () C:\Users\q\Downloads\HERE_beta_220.apk
2014-11-19 17:20 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 17:20 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 16:45 - 2014-11-17 20:09 - 00000000 ____D () C:\Kaspersky Rescue Disk 10.0
2014-11-16 21:02 - 2014-11-16 21:03 - 00000000 ____D () C:\Users\q\Desktop\Books
2014-11-13 20:30 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-13 20:30 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-13 20:30 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-13 20:30 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-13 20:30 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-13 20:30 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-13 20:30 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-13 20:30 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-13 20:30 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-13 20:30 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-13 20:30 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-13 20:30 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-13 20:30 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-13 20:30 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-13 20:30 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-13 20:30 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-13 20:30 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-13 20:14 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-13 20:14 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-13 20:14 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-13 20:14 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-13 20:14 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-13 20:14 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-13 20:13 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-13 20:13 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-13 20:13 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-13 20:13 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-13 20:13 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-13 20:13 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-13 20:13 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-13 20:13 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-13 20:13 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-13 20:13 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-13 20:13 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-13 20:13 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-13 20:13 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-13 20:13 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-13 20:13 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-13 20:12 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-13 20:12 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-10 17:28 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 17:28 - 2014-11-11 21:31 - 00000000 ____D () C:\Users\q\AppData\Roaming\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\Users\q\AppData\Local\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\ProgramData\Mozilla
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-09 21:45 - 2014-03-25 20:00 - 00000000 ____D () C:\FRST
2014-12-09 21:43 - 2013-12-11 15:34 - 00000000 ____D () C:\Users\q\AppData\Roaming\Skype
2014-12-09 21:42 - 2014-08-27 19:18 - 00000930 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job
2014-12-09 21:24 - 2014-11-04 20:38 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-09 20:57 - 2012-02-13 13:04 - 01978232 _____ () C:\Windows\WindowsUpdate.log
2014-12-09 20:55 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-09 20:55 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-09 20:48 - 2013-12-11 15:38 - 00000000 ____D () C:\Program Files\BatteryBar
2014-12-09 20:47 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-09 20:47 - 2009-07-14 05:45 - 00473208 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-09 20:39 - 2012-02-15 09:57 - 00000000 ____D () C:\Users\q\AppData\Local\CrashDumps
2014-12-09 20:24 - 2014-08-27 19:18 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job
2014-12-08 19:19 - 2009-07-14 06:13 - 00006222 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ____D () C:\ProgramData\Skype
2014-12-08 18:54 - 2012-02-14 19:51 - 00125320 _____ () C:\Users\q\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-06 22:45 - 2012-02-14 19:48 - 00000000 ____D () C:\Users\q
2014-11-30 07:09 - 2012-02-15 09:57 - 00000000 ____D () C:\Users\q\AppData\Roaming\Thinstall
2014-11-30 06:53 - 2014-03-05 19:39 - 00000000 ____D () C:\Windows\XSxS
2014-11-28 21:13 - 2014-05-02 14:41 - 00000000 ____D () C:\Users\q\AppData\Local\Downloaded Installations
2014-11-28 15:12 - 2014-03-16 11:16 - 00000000 ____D () C:\temp
2014-11-25 20:41 - 2014-11-04 20:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:41 - 2014-11-04 20:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 20:41 - 2014-11-04 20:38 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-16 17:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-15 22:37 - 2014-08-27 19:18 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA
2014-11-15 22:37 - 2014-08-27 19:18 - 00003500 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core
2014-11-13 21:06 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-13 21:03 - 2014-04-25 21:18 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 20:43 - 2011-10-12 19:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-13 20:39 - 2013-09-10 14:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 20:32 - 2011-10-12 20:16 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-13 18:15 - 2009-07-14 05:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-13 18:01 - 2013-12-11 15:38 - 00000000 ____D () C:\Users\q\AppData\Roaming\BatteryBar
2014-11-09 21:55 - 2014-10-07 20:27 - 00000932 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2014-11-09 21:55 - 2013-12-18 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2014-11-09 21:55 - 2013-12-18 23:24 - 00000000 ____D () C:\Program Files\Calibre2
Some content of TEMP:
====================
C:\Users\q\AppData\Local\Temp\BatteryBarSetup-3.6.5.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:0888F409
AlternateDataStreams: C:\ProgramData\TEMP:3440EB47
AlternateDataStreams: C:\ProgramData\TEMP:66633281
==================== Security Center ==================
AV: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\q\Desktop" je 146 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-12-2014
Ran by q (administrator) on KNI4 on 09-12-2014 21:45:32
Running from C:\Users\q\Desktop
Loaded Profile: q (Available profiles: q)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Dassault Systèmes) C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Flexera Software, Inc.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
(http://www.SteveMiller.net) D:\portables\PortableApps\puretext\PureText.exe
(PortableApps.com) D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(Miranda NG Team) D:\portables\PortableApps\miranda\Miranda64.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2918656 2011-01-12] (ESET)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [323128 2011-07-06] (Hewlett-Packard Company)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SystemExplorerAutoStart] => C:\Program Files (x86)\System Explorer\SystemExplorer.exe [3830632 2014-06-24] (Mister Group)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X]
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [ShowBatteryBar] => C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2014-09-19] ()
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Policies\system: [Wallpaper] c:\Windows\Web\Wallpaper\Characters\plocha.jpg
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Policies\system: [WallpaperStyle] 0
IFEO\taskmgr.exe: [Debugger] "C:\Program Files (x86)\System Explorer\SystemExplorer.exe"
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.3.lnk
ShortcutTarget: LibreOffice 4.3.lnk -> C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe ()
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk
ShortcutTarget: Miranda64 - odkaz.lnk -> D:\portables\PortableApps\miranda\Miranda64.exe (Miranda NG Team)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk
ShortcutTarget: PureText - odkaz.lnk -> D:\portables\PortableApps\puretext\PureText.exe (http://www.SteveMiller.net)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start - odkaz.lnk
ShortcutTarget: Start - odkaz.lnk -> D:\portables\Start.exe (PortableApps.com)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.10
Tcpip\..\Interfaces\{B06296C6-4AEA-4484-B8F1-455E2557F8AA}: [NameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/GoogleTalkPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/O1DPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=3 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=9 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10]
FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19]
FF Extension: Gmail panel - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2014-11-19]
FF Extension: gTranslate - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi [2014-11-19]
FF Extension: Adblock Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-10]
FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-12-16]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR StartMenuInternet: Google Chrome - C:\Users\test1\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [53920 2011-01-06] (Atheros Commnucations) [File not signed]
R2 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [123392 2014-03-14] (Dassault Systèmes) [File not signed]
S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [42360 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [810144 2011-01-12] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2011-12-16] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [1698360 2011-07-06] (Hewlett-Packard Company)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2014-04-25] (IDT, Inc.) [File not signed]
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-11-25] (Mister Group)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [38424 2010-10-18] (Google Inc)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [125296 2010-12-21] (ESET)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769304 2014-05-11] (http://www.ext2fsd.com)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
S3 GeneStor; C:\Windows\System32\DRIVERS\GeneStor.sys [58368 2014-05-17] (GenesysLogic)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-05-12] (Intel Corporation)
R3 mv2; C:\Windows\System32\DRIVERS\mv2.sys [12904 2012-02-17] (UVNC BVBA)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [328808 2010-10-28] (Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3073752 2014-04-25] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1863680 2012-03-30] (Sonix Co. Ltd.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512952 2014-04-25] (Sunplus)
S3 vserial; System32\DRIVERS\vserial.sys [X]
U3 wampapache; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-09 21:45 - 2014-12-09 21:46 - 00014678 _____ () C:\Users\q\Desktop\FRST.txt
2014-12-09 21:43 - 2014-12-09 21:44 - 02119680 _____ (Farbar) C:\Users\q\Desktop\FRST64.exe
2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
2014-12-09 21:29 - 2014-12-09 21:34 - 05937745 _____ () C:\Users\q\Downloads\MTK6582 MTK6589 MTK6592 ROOT.zip.part
2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit
2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe
2014-12-09 20:47 - 2014-12-09 20:47 - 00000056 _____ () C:\Windows\setupact.log
2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-09 20:46 - 2014-12-09 20:46 - 00005672 _____ () C:\Windows\PFRO.log
2014-12-08 18:37 - 2014-12-08 18:38 - 00009416 _____ () C:\Users\q\Downloads\services.m3u
2014-12-07 12:20 - 2014-12-07 12:20 - 00000000 ____D () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH
2014-12-06 23:57 - 2014-12-06 23:57 - 00000000 ____D () C:\Users\q\Downloads\code39
2014-12-06 23:56 - 2014-12-06 23:56 - 00002399 _____ () C:\Users\q\Downloads\code39.zip
2014-12-06 23:54 - 2014-12-06 23:54 - 00000000 ____D () C:\Users\q\Downloads\code_128
2014-12-06 23:53 - 2014-12-06 23:53 - 00002240 _____ () C:\Users\q\Downloads\code_128.zip
2014-12-06 23:39 - 2014-12-06 23:39 - 00000000 ____D () C:\Users\q\Downloads\free3of9
2014-12-06 23:38 - 2014-12-06 23:38 - 00005342 _____ () C:\Users\q\Downloads\free3of9.zip
2014-12-06 23:17 - 2014-12-07 00:22 - 00156154 _____ () C:\Users\q\Desktop\Backup_of_johndeere.cdr
2014-12-06 22:43 - 2014-12-06 22:43 - 00127053 _____ () C:\Users\q\Downloads\antigoni.zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(2).zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(1).zip
2014-12-06 22:11 - 2014-12-07 11:04 - 00156778 _____ () C:\Users\q\Desktop\johndeere.cdr
2014-12-06 22:10 - 2014-12-06 22:10 - 00000000 ____D () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com
2014-12-06 22:09 - 2014-12-06 22:10 - 00009029 _____ () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com.zip
2014-12-06 21:43 - 2014-12-06 21:43 - 00000000 ____D () C:\Users\q\Downloads\Media-Gothic
2014-12-06 21:42 - 2014-12-06 21:42 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic.zip
2014-12-06 21:11 - 2014-12-06 21:35 - 03330106 _____ () C:\Users\q\Desktop\IMG_0969.xcf
2014-12-06 19:51 - 2014-12-06 20:03 - 57897385 _____ () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH.zip
2014-12-01 22:08 - 2014-12-01 22:08 - 00711376 _____ () C:\Users\q\Downloads\oscamOSEmu_8933
2014-12-01 22:07 - 2014-12-01 22:07 - 00061800 _____ () C:\Users\q\Downloads\OSEmu
2014-12-01 22:05 - 2014-12-01 22:05 - 00164599 _____ () C:\Users\q\Downloads\OSEmu-1.02r-optimized-sh4-linux.zip
2014-12-01 22:03 - 2014-12-01 22:03 - 00171138 _____ () C:\Users\q\Downloads\OSEmu-1.02r-sh4-linux.zip
2014-12-01 21:43 - 2014-12-01 21:43 - 01235688 _____ () C:\Users\q\Downloads\oscam_emu.zip
2014-12-01 21:36 - 2014-12-01 21:38 - 00690803 _____ () C:\Users\q\Downloads\oscam-1.20-unstable_svn9812-OSEmu-1.02h-sh4-linux.zip
2014-12-01 21:20 - 2014-12-01 21:20 - 00474433 _____ () C:\Users\q\Downloads\oscam-svn10060-sh_4-webif-oscam-emu-patched.zip
2014-12-01 19:47 - 2014-12-01 19:47 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\q\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-30 18:41 - 2014-11-30 18:44 - 00000000 ____D () C:\Users\q\cr3
2014-11-30 07:57 - 2014-11-30 07:57 - 00000000 ____D () C:\Users\q\Documents\My Palettes
2014-11-30 07:12 - 2014-11-30 07:45 - 585322958 _____ () C:\Users\q\Downloads\CorelDRAWGSX6-v16.2.0.998-Portable.rar
2014-11-30 06:53 - 2014-11-30 06:54 - 00000000 ____D () C:\Windows\SysWOW64\spool
2014-11-28 21:15 - 2014-11-28 21:15 - 00002088 _____ () C:\Users\Public\Desktop\SDFormatter.lnk
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\Program Files (x86)\SDA
2014-11-28 20:55 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-28 20:53 - 2014-11-28 20:54 - 06286748 _____ () C:\Users\q\Downloads\SDFormatterv4.zip
2014-11-28 10:44 - 2014-11-28 10:45 - 06333290 _____ () C:\Users\q\Downloads\AmazonApps-release.apk
2014-11-21 16:54 - 2014-11-21 16:55 - 38662656 _____ () C:\Users\q\Downloads\HERE_beta_220.apk
2014-11-19 17:20 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 17:20 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 16:45 - 2014-11-17 20:09 - 00000000 ____D () C:\Kaspersky Rescue Disk 10.0
2014-11-16 21:02 - 2014-11-16 21:03 - 00000000 ____D () C:\Users\q\Desktop\Books
2014-11-13 20:30 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-13 20:30 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-13 20:30 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-13 20:30 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-13 20:30 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-13 20:30 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-13 20:30 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-13 20:30 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-13 20:30 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-13 20:30 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-13 20:30 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-13 20:30 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-13 20:30 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-13 20:30 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-13 20:30 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-13 20:30 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-13 20:30 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-13 20:14 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-13 20:14 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-13 20:14 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-13 20:14 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-13 20:14 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-13 20:14 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-13 20:13 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-13 20:13 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-13 20:13 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-13 20:13 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-13 20:13 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-13 20:13 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-13 20:13 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-13 20:13 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-13 20:13 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-13 20:13 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-13 20:13 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-13 20:13 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-13 20:13 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-13 20:13 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-13 20:13 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-13 20:12 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-13 20:12 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-10 17:28 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 17:28 - 2014-11-11 21:31 - 00000000 ____D () C:\Users\q\AppData\Roaming\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\Users\q\AppData\Local\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\ProgramData\Mozilla
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-09 21:45 - 2014-03-25 20:00 - 00000000 ____D () C:\FRST
2014-12-09 21:43 - 2013-12-11 15:34 - 00000000 ____D () C:\Users\q\AppData\Roaming\Skype
2014-12-09 21:42 - 2014-08-27 19:18 - 00000930 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job
2014-12-09 21:24 - 2014-11-04 20:38 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-09 20:57 - 2012-02-13 13:04 - 01978232 _____ () C:\Windows\WindowsUpdate.log
2014-12-09 20:55 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-09 20:55 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-09 20:48 - 2013-12-11 15:38 - 00000000 ____D () C:\Program Files\BatteryBar
2014-12-09 20:47 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-09 20:47 - 2009-07-14 05:45 - 00473208 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-09 20:39 - 2012-02-15 09:57 - 00000000 ____D () C:\Users\q\AppData\Local\CrashDumps
2014-12-09 20:24 - 2014-08-27 19:18 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job
2014-12-08 19:19 - 2009-07-14 06:13 - 00006222 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ____D () C:\ProgramData\Skype
2014-12-08 18:54 - 2012-02-14 19:51 - 00125320 _____ () C:\Users\q\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-06 22:45 - 2012-02-14 19:48 - 00000000 ____D () C:\Users\q
2014-11-30 07:09 - 2012-02-15 09:57 - 00000000 ____D () C:\Users\q\AppData\Roaming\Thinstall
2014-11-30 06:53 - 2014-03-05 19:39 - 00000000 ____D () C:\Windows\XSxS
2014-11-28 21:13 - 2014-05-02 14:41 - 00000000 ____D () C:\Users\q\AppData\Local\Downloaded Installations
2014-11-28 15:12 - 2014-03-16 11:16 - 00000000 ____D () C:\temp
2014-11-25 20:41 - 2014-11-04 20:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:41 - 2014-11-04 20:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 20:41 - 2014-11-04 20:38 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-16 17:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-15 22:37 - 2014-08-27 19:18 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA
2014-11-15 22:37 - 2014-08-27 19:18 - 00003500 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core
2014-11-13 21:06 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-13 21:03 - 2014-04-25 21:18 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 20:43 - 2011-10-12 19:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-13 20:39 - 2013-09-10 14:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 20:32 - 2011-10-12 20:16 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-13 18:15 - 2009-07-14 05:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-13 18:01 - 2013-12-11 15:38 - 00000000 ____D () C:\Users\q\AppData\Roaming\BatteryBar
2014-11-09 21:55 - 2014-10-07 20:27 - 00000932 _____ () C:\Users\Public\Desktop\calibre 64bit - E-book management.lnk
2014-11-09 21:55 - 2013-12-18 23:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre 64bit - E-book Management
2014-11-09 21:55 - 2013-12-18 23:24 - 00000000 ____D () C:\Program Files\Calibre2
Some content of TEMP:
====================
C:\Users\q\AppData\Local\Temp\BatteryBarSetup-3.6.5.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:0888F409
AlternateDataStreams: C:\ProgramData\TEMP:3440EB47
AlternateDataStreams: C:\ProgramData\TEMP:66633281
==================== Security Center ==================
AV: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\q\Desktop" je 146 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.zip
- (6.46 KiB) Staženo 40 x
Re: spomaleny pocitac, eset odstránil viacere infiltracie



- Ulozte nejlepe na plochu
- Ukoncete vsechny programy
- Po spusteni probehne stazeni databaze
- Kliknete na Scan a nasledne Clean
- Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte
Re: spomaleny pocitac, eset odstránil viacere infiltracie
Eset je original asi vsetko v Nb je oficialne neviem preco je tam NOD4 ale na to ja nemam dosah snazim sa len manzelke spojazdnit stroj ked spravca u nich v skole to ma v pazi.
Pripajam pozadovany LOG:
# AdwCleaner v4.105 - Report created 09/12/2014 at 22:04:31
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : q - KNI4
# Running from : C:\Users\q\Desktop\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\eSupport.com
Folder Deleted : C:\Users\q\AppData\Local\eSupport.com
Folder Deleted : C:\Users\q\AppData\Local\CrashRpt
Folder Deleted : C:\Users\q\AppData\Roaming\pdfforge
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\eSupport.com
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Mozilla Firefox v35.0 (x86 sk)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [1490 octets] - [09/12/2014 22:02:26]
AdwCleaner[S0].txt - [1377 octets] - [09/12/2014 22:04:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1437 octets] ##########
Pripajam pozadovany LOG:
# AdwCleaner v4.105 - Report created 09/12/2014 at 22:04:31
# Updated 08/12/2014 by Xplode
# Database : 2014-12-08.2 [Live]
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : q - KNI4
# Running from : C:\Users\q\Desktop\adwcleaner_4.105.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\eSupport.com
Folder Deleted : C:\Users\q\AppData\Local\eSupport.com
Folder Deleted : C:\Users\q\AppData\Local\CrashRpt
Folder Deleted : C:\Users\q\AppData\Roaming\pdfforge
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKCU\Software\eSupport.com
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Mozilla Firefox v35.0 (x86 sk)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [1490 octets] - [09/12/2014 22:02:26]
AdwCleaner[S0].txt - [1377 octets] - [09/12/2014 22:04:31]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1437 octets] ##########
Re: spomaleny pocitac, eset odstránil viacere infiltracie




Re: spomaleny pocitac, eset odstránil viacere infiltracie
ale ano, rad by som pokracoval...
Re: spomaleny pocitac, eset odstránil viacere infiltracie


- Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
- Do okna vlozte skript nize
Kód: Vybrat vše
autoclean; resethosts; emptyclsid; IEdefaults; FFdefaults; CHRdefaults; emptyIEcache; emptyFFcache; emptyCHRcache; emptyalltemp; emptyflash; emptyjava; emptyrecycle.bin;
- Nasledne kliknete na Run Script
- PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem
Re: spomaleny pocitac, eset odstránil viacere infiltracie
Prikladam pozadovany log:
Zoek.exe v5.0.0.0 Updated 08-December-2014
Tool run by q on ut 09. 12. 2014 at 22:25:15,79.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\q\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
9. 12. 2014 22:27:10 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\VideoLAN deleted successfully
C:\PROGRA~2\Xenocode deleted successfully
C:\PROGRA~3\Acunetix WVS 9 deleted successfully
C:\PROGRA~3\Bitdefender deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\q\AppData\Roaming\Media Player Classic deleted successfully
C:\Users\q\AppData\Local\calibre-cache deleted successfully
C:\Users\q\AppData\Local\CrashDumps deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("services.sync.prefs.sync.browser.search.selectedEngine", true);
Added to C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----
prefs_201409.12._2239_.backup
==== Deleting Files \ Folders ======================
C:\Users\q\AppData\Roaming\burnaware.ini deleted
C:\Users\q\AppData\Roaming\Thinstall deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
"C:\ProgramData\TEMP" deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
- Undetermined - feedly@devhd
- Undetermined - {aff87fa2-a58e-4edd-b852-0a20203c1e17}
- Undetermined - gmail_panel@alejandrobrizuela.com.ar
- Undetermined - firegestures@xuldev.org
- feedly - %ProfilePath%\extensions\feedly@devhd.xpi
- FireGestures - %ProfilePath%\extensions\firegestures@xuldev.org.xpi
- Gmail panel - %ProfilePath%\extensions\gmail_panel@alejandrobrizuela.com.ar.xpi
- gTranslate - %ProfilePath%\extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Tab Mix Plus - %ProfilePath%\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
8303B3CEC05500F763B4FA75210598BB - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll - Shockwave Flash
D2377C9458EFEB094E38B8C874AA214C - C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
76EFD64CD206B93E2EB5320A23C19AD7 - C:\Users\q\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
2AB6A7F373290AE20A19CF5F306E8C97 - C:\Users\q\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
8352E35875F8A69C39550FE991BA23F5 - D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll - Foxit Reader Plugin for Mozilla
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\q\AppData\Local\Google\Chrome deleted
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.sk/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.sk/"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
Nothing found to reset
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\357F2D0C will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0GLMZHJ will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LACVMBJE will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRHLTJ72 will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\q\AppData\Local\Mozilla\Firefox\Profiles\mvzl8rvh.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=70 folders=40 5676230 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\q\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\q\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\357F2D0C" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0GLMZHJ" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LACVMBJE" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRHLTJ72" not found
==== EOF on ut 09. 12. 2014 at 22:45:39,01 ======================
Zoek.exe v5.0.0.0 Updated 08-December-2014
Tool run by q on ut 09. 12. 2014 at 22:25:15,79.
Microsoft Windows 7 Professional 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\q\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
9. 12. 2014 22:27:10 Zoek.exe System Restore Point Created Succesfully.
==== Reset Hosts File ======================
# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
# localhost name resolution is handle within DNS itself.
127.0.0.1 localhost
::1 localhost
==== Empty Folders Check ======================
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\VideoLAN deleted successfully
C:\PROGRA~2\Xenocode deleted successfully
C:\PROGRA~3\Acunetix WVS 9 deleted successfully
C:\PROGRA~3\Bitdefender deleted successfully
C:\PROGRA~3\Oracle deleted successfully
C:\Users\q\AppData\Roaming\Media Player Classic deleted successfully
C:\Users\q\AppData\Local\calibre-cache deleted successfully
C:\Users\q\AppData\Local\CrashDumps deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F4E39681-15F8-4fda-B8A3-B5C98378F2F3} deleted successfully
==== Deleting CLSID Registry Values ======================
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("services.sync.prefs.sync.browser.search.selectedEngine", true);
Added to C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.com");
user_pref("browser.search.defaulturl", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.newtab.url", "http://www.google.com/");
user_pref("browser.search.defaultengine", "Google");
user_pref("browser.search.defaultenginename", "Google");
user_pref("browser.search.selectedEngine", "Google");
user_pref("browser.search.order.1", "Google");
user_pref("keyword.URL", "http://www.google.com/search?btnG=Google+Search&q=");
user_pref("browser.search.suggest.enabled", true);
user_pref("browser.search.useDBForOrder", true);
ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
user.js not found
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----
prefs_201409.12._2239_.backup
==== Deleting Files \ Folders ======================
C:\Users\q\AppData\Roaming\burnaware.ini deleted
C:\Users\q\AppData\Roaming\Thinstall deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
"C:\ProgramData\TEMP" deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
- Undetermined - feedly@devhd
- Undetermined - {aff87fa2-a58e-4edd-b852-0a20203c1e17}
- Undetermined - gmail_panel@alejandrobrizuela.com.ar
- Undetermined - firegestures@xuldev.org
- feedly - %ProfilePath%\extensions\feedly@devhd.xpi
- FireGestures - %ProfilePath%\extensions\firegestures@xuldev.org.xpi
- Gmail panel - %ProfilePath%\extensions\gmail_panel@alejandrobrizuela.com.ar.xpi
- gTranslate - %ProfilePath%\extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- Tab Mix Plus - %ProfilePath%\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
8303B3CEC05500F763B4FA75210598BB - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll - Shockwave Flash
D2377C9458EFEB094E38B8C874AA214C - C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll - Google Update
76EFD64CD206B93E2EB5320A23C19AD7 - C:\Users\q\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll - Google Talk Plugin
2AB6A7F373290AE20A19CF5F306E8C97 - C:\Users\q\AppData\Roaming\Mozilla\plugins\npo1d.dll - Google Talk Plugin Video Renderer
D7324EB1EDCB8990F8522DE0311359E9 - C:\Windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
8352E35875F8A69C39550FE991BA23F5 - D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll - Foxit Reader Plugin for Mozilla
87132527E2256CF6683A18C4EB34DD3B - C:\Windows\system32\Wat\npWatWeb.dll - Windows Activation Technologies
15E298B5EC5B89C5994A59863969D9FF - C:\Windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Fake Chromium Profiles Check ======================
Fake profile C:\Users\q\AppData\Local\Google\Chrome deleted
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.sk/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.sk/"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
==== Reset Google Chrome ======================
Nothing found to reset
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe deleted successfully
==== Empty IE Cache ======================
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\357F2D0C will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0GLMZHJ will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LACVMBJE will be deleted at reboot
C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRHLTJ72 will be deleted at reboot
==== Empty FireFox Cache ======================
C:\Users\q\AppData\Local\Mozilla\Firefox\Profiles\mvzl8rvh.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=70 folders=40 5676230 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\q\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\q\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\357F2D0C" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0GLMZHJ" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LACVMBJE" not found
"C:\Users\q\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SRHLTJ72" not found
==== EOF on ut 09. 12. 2014 at 22:45:39,01 ======================
Re: spomaleny pocitac, eset odstránil viacere infiltracie
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-12-2014
Ran by q (administrator) on KNI4 on 10-12-2014 16:13:24
Running from C:\Users\q\Desktop
Loaded Profile: q (Available profiles: q)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
(Dassault Systèmes) C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe
(Motorola Solutions, Inc.) C:\Program Files\Motorola\Bluetooth\obexsrv.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Flexera Software, Inc.) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Mister Group) C:\Program Files (x86)\System Explorer\SystemExplorer.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 4\program\soffice.bin
(Miranda NG Team) D:\portables\PortableApps\miranda\Miranda64.exe
(http://www.SteveMiller.net) D:\portables\PortableApps\puretext\PureText.exe
(Mister Group) C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
(PortableApps.com) D:\portables\PortableApps\PortableApps.com\PortableAppsPlatform.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2918656 2011-01-12] (ESET)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2804976 2013-10-30] (Synaptics Incorporated)
HKLM-x32\...\Run: [QLBController] => C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe [323128 2011-07-06] (Hewlett-Packard Company)
HKLM-x32\...\Run: [NUSB3MON] => c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2011-04-14] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SystemExplorerAutoStart] => C:\Program Files (x86)\System Explorer\SystemExplorer.exe [3830632 2014-06-24] (Mister Group)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X]
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [ShowBatteryBar] => C:\Program Files\BatteryBar\ShowBatteryBar.exe [89600 2014-09-19] ()
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LibreOffice 4.3.lnk
ShortcutTarget: LibreOffice 4.3.lnk -> C:\Program Files (x86)\LibreOffice 4\program\quickstart.exe ()
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk
ShortcutTarget: Miranda64 - odkaz.lnk -> D:\portables\PortableApps\miranda\Miranda64.exe (Miranda NG Team)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk
ShortcutTarget: PureText - odkaz.lnk -> D:\portables\PortableApps\puretext\PureText.exe (http://www.SteveMiller.net)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start - odkaz.lnk
ShortcutTarget: Start - odkaz.lnk -> D:\portables\Start.exe (PortableApps.com)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-667187236-2916497924-1121132568-1005 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.10
Tcpip\..\Interfaces\{B06296C6-4AEA-4484-B8F1-455E2557F8AA}: [NameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> D:\portables\PortableApps\FoxitReaderPortable\App\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nokia.com/EnablerPlugin -> C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/GoogleTalkPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @talk.google.com/O1DPlugin -> C:\Users\q\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=3 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-667187236-2916497924-1121132568-1005: @tools.google.com/Google Update;version=9 -> C:\Users\q\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\q\AppData\Roaming\mozilla\plugins\npo1d.dll (Google)
FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10]
FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19]
FF Extension: Gmail panel - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\gmail_panel@alejandrobrizuela.com.ar.xpi [2014-11-19]
FF Extension: gTranslate - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{aff87fa2-a58e-4edd-b852-0a20203c1e17}.xpi [2014-11-19]
FF Extension: Adblock Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-10]
FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011-12-16]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR StartMenuInternet: Google Chrome - C:\Users\test1\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-01-06] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [53920 2011-01-06] (Atheros Commnucations) [File not signed]
R2 DraftSight API Service; C:\Program Files\Dassault Systemes\DraftSight\bin\dsHttpApiService.exe [123392 2014-03-14] (Dassault Systèmes) [File not signed]
S3 EhttpSrv; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [42360 2011-01-12] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [810144 2011-01-12] (ESET)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2011-12-16] (Macrovision Europe Ltd.) [File not signed]
R2 hpHotkeyMonitor; C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [1698360 2011-07-06] (Hewlett-Packard Company)
R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-26] (Microsoft Corporation) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [327680 2014-04-25] (IDT, Inc.) [File not signed]
R3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [821720 2012-11-25] (Mister Group)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [38424 2010-10-18] (Google Inc)
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [170640 2010-12-21] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [141264 2010-12-21] (ESET)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [125296 2010-12-21] (ESET)
R1 Ext2Fsd; C:\Windows\System32\Drivers\Ext2Fsd.sys [769304 2014-05-11] (http://www.ext2fsd.com)
R0 FSProFilter; C:\Windows\System32\Drivers\FSPFltd.sys [54848 2010-07-22] (FSPro Labs)
S3 GeneStor; C:\Windows\System32\DRIVERS\GeneStor.sys [58368 2014-05-17] (GenesysLogic)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-05-12] (Intel Corporation)
R3 mv2; C:\Windows\System32\DRIVERS\mv2.sys [12904 2012-02-17] (UVNC BVBA)
S3 RTLE8023x64; C:\Windows\System32\DRIVERS\Rtenic64.sys [328808 2010-10-28] (Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3073752 2014-04-25] (Realtek Semiconductor Corporation )
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1863680 2012-03-30] (Sonix Co. Ltd.)
R3 SPUVCbv; C:\Windows\System32\Drivers\SPUVCbv_x64.sys [1512952 2014-04-25] (Sunplus)
S3 vserial; System32\DRIVERS\vserial.sys [X]
U3 wampapache; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-10 16:13 - 2014-12-10 16:14 - 00015037 _____ () C:\Users\q\Desktop\FRST.txt
2014-12-09 22:44 - 2014-12-09 22:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-09 22:26 - 2014-12-09 22:45 - 00009813 _____ () C:\zoek-results.log
2014-12-09 22:25 - 2014-12-09 22:39 - 00000000 ____D () C:\zoek_backup
2014-12-09 22:23 - 2014-12-09 22:24 - 01295360 _____ () C:\Users\q\Desktop\zoek.exe
2014-12-09 22:02 - 2014-12-09 22:04 - 00000000 ____D () C:\AdwCleaner
2014-12-09 22:01 - 2014-12-09 22:01 - 02166272 _____ () C:\Users\q\Desktop\adwcleaner_4.105.exe
2014-12-09 21:48 - 2014-12-09 21:48 - 00006610 _____ () C:\Users\q\Desktop\Addition.zip
2014-12-09 21:43 - 2014-12-09 21:44 - 02119680 _____ (Farbar) C:\Users\q\Desktop\FRST64.exe
2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
2014-12-09 21:29 - 2014-12-09 21:34 - 05937745 _____ () C:\Users\q\Downloads\MTK6582 MTK6589 MTK6592 ROOT.zip.part
2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit
2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe
2014-12-09 20:47 - 2014-12-09 22:45 - 00000168 _____ () C:\Windows\setupact.log
2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-09 20:46 - 2014-12-09 22:45 - 00006306 _____ () C:\Windows\PFRO.log
2014-12-08 18:37 - 2014-12-08 18:38 - 00009416 _____ () C:\Users\q\Downloads\services.m3u
2014-12-07 12:20 - 2014-12-07 12:20 - 00000000 ____D () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH
2014-12-06 23:57 - 2014-12-06 23:57 - 00000000 ____D () C:\Users\q\Downloads\code39
2014-12-06 23:56 - 2014-12-06 23:56 - 00002399 _____ () C:\Users\q\Downloads\code39.zip
2014-12-06 23:54 - 2014-12-06 23:54 - 00000000 ____D () C:\Users\q\Downloads\code_128
2014-12-06 23:53 - 2014-12-06 23:53 - 00002240 _____ () C:\Users\q\Downloads\code_128.zip
2014-12-06 23:39 - 2014-12-06 23:39 - 00000000 ____D () C:\Users\q\Downloads\free3of9
2014-12-06 23:38 - 2014-12-06 23:38 - 00005342 _____ () C:\Users\q\Downloads\free3of9.zip
2014-12-06 23:17 - 2014-12-07 00:22 - 00156154 _____ () C:\Users\q\Desktop\Backup_of_johndeere.cdr
2014-12-06 22:43 - 2014-12-06 22:43 - 00127053 _____ () C:\Users\q\Downloads\antigoni.zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(2).zip
2014-12-06 22:29 - 2014-12-06 22:29 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic(1).zip
2014-12-06 22:11 - 2014-12-07 11:04 - 00156778 _____ () C:\Users\q\Desktop\johndeere.cdr
2014-12-06 22:10 - 2014-12-06 22:10 - 00000000 ____D () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com
2014-12-06 22:09 - 2014-12-06 22:10 - 00009029 _____ () C:\Users\q\Downloads\john-deere-vector-logo-A48DECD651-seeklogo.com.zip
2014-12-06 21:43 - 2014-12-06 21:43 - 00000000 ____D () C:\Users\q\Downloads\Media-Gothic
2014-12-06 21:42 - 2014-12-06 21:42 - 00007997 _____ () C:\Users\q\Downloads\Media-Gothic.zip
2014-12-06 21:11 - 2014-12-06 21:35 - 03330106 _____ () C:\Users\q\Desktop\IMG_0969.xcf
2014-12-06 19:51 - 2014-12-06 20:03 - 57897385 _____ () C:\Users\q\Downloads\PKT_GM7162_E2_HYPERION_v4_5_FLASH.zip
2014-12-01 22:08 - 2014-12-01 22:08 - 00711376 _____ () C:\Users\q\Downloads\oscamOSEmu_8933
2014-12-01 22:07 - 2014-12-01 22:07 - 00061800 _____ () C:\Users\q\Downloads\OSEmu
2014-12-01 22:05 - 2014-12-01 22:05 - 00164599 _____ () C:\Users\q\Downloads\OSEmu-1.02r-optimized-sh4-linux.zip
2014-12-01 22:03 - 2014-12-01 22:03 - 00171138 _____ () C:\Users\q\Downloads\OSEmu-1.02r-sh4-linux.zip
2014-12-01 21:43 - 2014-12-01 21:43 - 01235688 _____ () C:\Users\q\Downloads\oscam_emu.zip
2014-12-01 21:36 - 2014-12-01 21:38 - 00690803 _____ () C:\Users\q\Downloads\oscam-1.20-unstable_svn9812-OSEmu-1.02h-sh4-linux.zip
2014-12-01 21:20 - 2014-12-01 21:20 - 00474433 _____ () C:\Users\q\Downloads\oscam-svn10060-sh_4-webif-oscam-emu-patched.zip
2014-12-01 19:47 - 2014-12-01 19:47 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\q\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-30 18:41 - 2014-11-30 18:44 - 00000000 ____D () C:\Users\q\cr3
2014-11-30 07:57 - 2014-11-30 07:57 - 00000000 ____D () C:\Users\q\Documents\My Palettes
2014-11-30 07:12 - 2014-11-30 07:45 - 585322958 _____ () C:\Users\q\Downloads\CorelDRAWGSX6-v16.2.0.998-Portable.rar
2014-11-30 06:53 - 2014-11-30 06:54 - 00000000 ____D () C:\Windows\SysWOW64\spool
2014-11-28 21:15 - 2014-11-28 21:15 - 00002088 _____ () C:\Users\Public\Desktop\SDFormatter.lnk
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SDFormatter
2014-11-28 21:15 - 2014-11-28 21:15 - 00000000 ____D () C:\Program Files (x86)\SDA
2014-11-28 20:55 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-28 20:53 - 2014-11-28 20:54 - 06286748 _____ () C:\Users\q\Downloads\SDFormatterv4.zip
2014-11-28 10:44 - 2014-11-28 10:45 - 06333290 _____ () C:\Users\q\Downloads\AmazonApps-release.apk
2014-11-21 16:54 - 2014-11-21 16:55 - 38662656 _____ () C:\Users\q\Downloads\HERE_beta_220.apk
2014-11-19 17:20 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 17:20 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 17:20 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-17 16:45 - 2014-11-17 20:09 - 00000000 ____D () C:\Kaspersky Rescue Disk 10.0
2014-11-16 21:02 - 2014-11-16 21:03 - 00000000 ____D () C:\Users\q\Desktop\Books
2014-11-13 20:30 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-13 20:30 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-13 20:30 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-13 20:30 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-13 20:30 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-13 20:30 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-13 20:30 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-13 20:30 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-13 20:30 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-13 20:30 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-13 20:30 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-13 20:30 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-13 20:30 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-13 20:30 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-13 20:30 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-13 20:30 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-13 20:30 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-13 20:30 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-13 20:30 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-13 20:30 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-13 20:30 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-13 20:30 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-13 20:30 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-13 20:30 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-13 20:30 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-13 20:30 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-13 20:30 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-13 20:30 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-13 20:30 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-13 20:30 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-13 20:30 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-13 20:30 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-13 20:30 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-13 20:30 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-13 20:14 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-13 20:14 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-13 20:14 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-13 20:14 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-13 20:14 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-13 20:14 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-13 20:14 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-13 20:14 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-13 20:14 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-13 20:13 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-13 20:13 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-13 20:13 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-13 20:13 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-13 20:13 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-13 20:13 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-13 20:13 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-13 20:13 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-13 20:13 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-13 20:13 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-13 20:13 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-13 20:13 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-13 20:13 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-13 20:13 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-13 20:13 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-13 20:13 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-13 20:13 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-13 20:12 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-13 20:12 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-10 17:28 - 2014-12-09 20:46 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-10 17:28 - 2014-11-11 21:31 - 00000000 ____D () C:\Users\q\AppData\Roaming\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00001161 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00001149 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\Users\q\AppData\Local\Mozilla
2014-11-10 17:28 - 2014-11-10 17:28 - 00000000 ____D () C:\ProgramData\Mozilla
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-10 16:13 - 2014-03-25 20:00 - 00000000 ____D () C:\FRST
2014-12-10 16:11 - 2014-08-27 19:18 - 00000930 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job
2014-12-10 16:10 - 2014-11-04 20:38 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-10 16:10 - 2013-12-11 15:34 - 00000000 ____D () C:\Users\q\AppData\Roaming\Skype
2014-12-09 22:53 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-09 22:53 - 2009-07-14 05:45 - 00021680 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-09 22:45 - 2012-03-29 14:40 - 00000008 __RSH () C:\Users\q\ntuser.pol
2014-12-09 22:45 - 2012-02-14 19:48 - 00000000 ____D () C:\Users\q
2014-12-09 22:45 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-09 22:44 - 2012-02-13 13:04 - 02002608 _____ () C:\Windows\WindowsUpdate.log
2014-12-09 22:42 - 2014-08-27 19:18 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job
2014-12-09 22:40 - 2012-02-15 07:49 - 00000000 ____D () C:\Users\q\AppData\Local\Google
2014-12-09 22:39 - 2009-07-14 04:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-12-09 20:48 - 2013-12-11 15:38 - 00000000 ____D () C:\Program Files\BatteryBar
2014-12-09 20:47 - 2009-07-14 05:45 - 00473208 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-08 19:19 - 2009-07-14 06:13 - 00006222 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-08 18:56 - 2013-12-11 15:32 - 00000000 ____D () C:\ProgramData\Skype
2014-12-08 18:54 - 2012-02-14 19:51 - 00125320 _____ () C:\Users\q\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-30 06:53 - 2014-03-05 19:39 - 00000000 ____D () C:\Windows\XSxS
2014-11-28 21:13 - 2014-05-02 14:41 - 00000000 ____D () C:\Users\q\AppData\Local\Downloaded Installations
2014-11-28 15:12 - 2014-03-16 11:16 - 00000000 ____D () C:\temp
2014-11-25 20:41 - 2014-11-04 20:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-25 20:41 - 2014-11-04 20:38 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-25 20:41 - 2014-11-04 20:38 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-16 17:21 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-15 22:37 - 2014-08-27 19:18 - 00003896 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA
2014-11-15 22:37 - 2014-08-27 19:18 - 00003500 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core
2014-11-13 21:06 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-13 21:03 - 2014-04-25 21:18 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 20:43 - 2011-10-12 19:48 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-13 20:39 - 2013-09-10 14:43 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-13 20:32 - 2011-10-12 20:16 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-13 18:15 - 2009-07-14 05:57 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-11-13 18:01 - 2013-12-11 15:38 - 00000000 ____D () C:\Users\q\AppData\Roaming\BatteryBar
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET NOD32 Antivirus 4.2 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\q\Desktop" je 149 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Re: spomaleny pocitac, eset odstránil viacere infiltracie

- Spustte poznamkovy blok (Start-spustit-notepad)
- Zkopirujte skript nize
Kód: Vybrat vše
Start CloseProcesses: HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X] HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.) Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10] FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19] FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19] 2014-12-10 16:13 - 2014-12-10 16:14 - 00015037 _____ () C:\Users\q\Desktop\FRST.txt 2014-12-09 22:44 - 2014-12-09 22:25 - 00024064 _____ () C:\Windows\zoek-delete.exe 2014-12-09 22:26 - 2014-12-09 22:45 - 00009813 _____ () C:\zoek-results.log 2014-12-09 22:25 - 2014-12-09 22:39 - 00000000 ____D () C:\zoek_backup 2014-12-09 22:23 - 2014-12-09 22:24 - 01295360 _____ () C:\Users\q\Desktop\zoek.exe 2014-12-09 22:02 - 2014-12-09 22:04 - 00000000 ____D () C:\AdwCleaner 2014-12-09 22:01 - 2014-12-09 22:01 - 02166272 _____ () C:\Users\q\Desktop\adwcleaner_4.105.exe 2014-12-09 21:48 - 2014-12-09 21:48 - 00006610 _____ () C:\Users\q\Desktop\Addition.zip 2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe 2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro 2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit 2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe 2014-12-09 20:47 - 2014-12-09 22:45 - 00000168 _____ () C:\Windows\setupact.log 2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log 2014-12-09 20:46 - 2014-12-09 22:45 - 00006306 _____ () C:\Windows\PFRO.log Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe Hosts: EmptyTemp: Reboot: End
- Ulozte vytvoreny TXT jako fixlist.txt
- Presunte vytvoreny fixlist vedle FRST

- Kliknete na Fix
- Probehne oprava a vytvori log Fixlog.txt

Re: spomaleny pocitac, eset odstránil viacere infiltracie
Ahoj,
pripajam fixlog.txt
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2014
Ran by q at 2014-12-11 16:39:47 Run:1
Running from C:\Users\q\Desktop
Loaded Profile: q (Available profiles: q)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X]
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10]
FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19]
FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19]
2014-12-10 16:13 - 2014-12-10 16:14 - 00015037 _____ () C:\Users\q\Desktop\FRST.txt
2014-12-09 22:44 - 2014-12-09 22:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-09 22:26 - 2014-12-09 22:45 - 00009813 _____ () C:\zoek-results.log
2014-12-09 22:25 - 2014-12-09 22:39 - 00000000 ____D () C:\zoek_backup
2014-12-09 22:23 - 2014-12-09 22:24 - 01295360 _____ () C:\Users\q\Desktop\zoek.exe
2014-12-09 22:02 - 2014-12-09 22:04 - 00000000 ____D () C:\AdwCleaner
2014-12-09 22:01 - 2014-12-09 22:01 - 02166272 _____ () C:\Users\q\Desktop\adwcleaner_4.105.exe
2014-12-09 21:48 - 2014-12-09 21:48 - 00006610 _____ () C:\Users\q\Desktop\Addition.zip
2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit
2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe
2014-12-09 20:47 - 2014-12-09 22:45 - 00000168 _____ () C:\Windows\setupact.log
2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-09 20:46 - 2014-12-09 22:45 - 00006306 _____ () C:\Windows\PFRO.log
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully.
C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk => Moved successfully.
C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk => Moved successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi => Moved successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi => Moved successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi => Moved successfully.
"C:\Users\q\Desktop\FRST.txt" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\q\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\q\Desktop\adwcleaner_4.105.exe => Moved successfully.
C:\Users\q\Desktop\Addition.zip => Moved successfully.
C:\Users\q\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\q\Downloads\RSITx64.exe => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 131.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
pripajam fixlog.txt
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 09-12-2014
Ran by q at 2014-12-11 16:39:47 Run:1
Running from C:\Users\q\Desktop
Loaded Profile: q (Available profiles: q)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [] => [X]
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30524520 2014-11-27] (Skype Technologies S.A.)
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk
Startup: C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Extension: feedly - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi [2014-11-10]
FF Extension: FireGestures - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi [2014-11-19]
FF Extension: Tab Mix Plus - C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-11-19]
2014-12-10 16:13 - 2014-12-10 16:14 - 00015037 _____ () C:\Users\q\Desktop\FRST.txt
2014-12-09 22:44 - 2014-12-09 22:25 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-12-09 22:26 - 2014-12-09 22:45 - 00009813 _____ () C:\zoek-results.log
2014-12-09 22:25 - 2014-12-09 22:39 - 00000000 ____D () C:\zoek_backup
2014-12-09 22:23 - 2014-12-09 22:24 - 01295360 _____ () C:\Users\q\Desktop\zoek.exe
2014-12-09 22:02 - 2014-12-09 22:04 - 00000000 ____D () C:\AdwCleaner
2014-12-09 22:01 - 2014-12-09 22:01 - 02166272 _____ () C:\Users\q\Desktop\adwcleaner_4.105.exe
2014-12-09 21:48 - 2014-12-09 21:48 - 00006610 _____ () C:\Users\q\Desktop\Addition.zip
2014-12-09 21:43 - 2014-12-09 21:43 - 00112640 _____ (forum.viry.cz) C:\Users\q\Desktop\FRSTLauncher.exe
2014-12-09 21:00 - 2014-12-09 21:10 - 00000000 ____D () C:\Program Files\trend micro
2014-12-09 21:00 - 2014-12-09 21:01 - 00000000 ____D () C:\rsit
2014-12-09 20:58 - 2014-12-09 20:59 - 01222144 _____ () C:\Users\q\Downloads\RSITx64.exe
2014-12-09 20:47 - 2014-12-09 22:45 - 00000168 _____ () C:\Windows\setupact.log
2014-12-09 20:47 - 2014-12-09 20:47 - 00000000 _____ () C:\Windows\setuperr.log
2014-12-09 20:46 - 2014-12-09 22:45 - 00006306 _____ () C:\Windows\PFRO.log
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => C:\Users\q\AppData\Local\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
Reboot:
End
*****************
Processes closed successfully.
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.
HKU\S-1-5-21-667187236-2916497924-1121132568-1005\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value deleted successfully.
C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Miranda64 - odkaz.lnk => Moved successfully.
C:\Users\q\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureText - odkaz.lnk => Moved successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\feedly@devhd.xpi => Moved successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\firegestures@xuldev.org.xpi => Moved successfully.
C:\Users\q\AppData\Roaming\Mozilla\Firefox\Profiles\mvzl8rvh.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi => Moved successfully.
"C:\Users\q\Desktop\FRST.txt" => File/Directory not found.
C:\Windows\zoek-delete.exe => Moved successfully.
C:\zoek-results.log => Moved successfully.
C:\zoek_backup => Moved successfully.
C:\Users\q\Desktop\zoek.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Users\q\Desktop\adwcleaner_4.105.exe => Moved successfully.
C:\Users\q\Desktop\Addition.zip => Moved successfully.
C:\Users\q\Desktop\FRSTLauncher.exe => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\rsit => Moved successfully.
C:\Users\q\Downloads\RSITx64.exe => Moved successfully.
C:\Windows\setupact.log => Moved successfully.
C:\Windows\setuperr.log => Moved successfully.
C:\Windows\PFRO.log => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005Core.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-667187236-2916497924-1121132568-1005UA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 131.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: spomaleny pocitac, eset odstránil viacere infiltracie
Jak se chova pocitac, problemy zmizely??
Re: spomaleny pocitac, eset odstránil viacere infiltracie
ano vyzera ze pocitac ide plynulo a nezamrza, super dakujem
, vsimol som si ze ste mi z Firefoxu odstranili viacere rozsirenia, sposobovali ony problemy alebo boli nejako inak nebezpecne?
