Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o radu jak se zbavit AVG

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Prosím o radu jak se zbavit AVG

#1 Příspěvek od rudy630 »

Prosím o radu jak se zbavit AVG. V nainstalovaných programech ho nelze najít. Je umístěn v C:Program data>AVG. Zkoušel jsem CCleaner>0, dále Adwcleaner>0. Prostě tuto položku nemůžu odstranit. Jinak používám CIS Premium. Log přikládám.

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015
Ran by Ruda (administrator) on RUDA-PC on 10-01-2015 00:11:13
Running from C:\PerfLogs\Desktop
Loaded Profile: Ruda (Available profiles: Ruda & Ruda-PC-2 & Guest & Classic .NET AppPool & DefaultAppPool)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Windows\System32\CISVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\Program Files\COMODO\COMODO Programs Manager\CPMservice.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(SPEEDbit) C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAcceleratorService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDGesture.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
(iSkySoft) C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_235.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2661672 2012-02-19] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [361984 2011-05-26] (Alcor Micro Corp.)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [1023616 2012-05-31] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [801920 2012-05-31] (Atheros Commnucations)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1297112 2014-12-09] (COMODO)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292088 2000-01-01] (Intel Corporation)
HKLM-x32\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [102568 2012-02-21] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-03] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [322208 2012-06-25] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174752 2012-06-19] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-12-25] (Comodo Security Solutions, Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2066432 2015-01-07] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [759712 2014-09-12] (Adobe Systems Incorporated)
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Facebook Update] => C:\Users\Ruda\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-12-18] (Facebook Inc.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs: , C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [178632 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: , c:\windows\syswow64\nvinit.dll => c:\windows\syswow64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
AppInit_DLLs-x32: , C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [165760 2014-12-13] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe ()
Startup: C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SystemExplorerDisabled ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
BootExecute: autocheck autochk * cnat
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-841361005-909514878-2309378359-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 -> SuggestionsURL_JSON http://api.widdit.com/suggestions/?form ... earchTerms}
SearchScopes: HKLM-x32 -> TopResultURLFallback http://search.certified-toolbar.com?si= ... earchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {1E1F17B7-F889-4480-8A29-31EC9A9EFF8C} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {1E2C0E9F-5A57-404C-B006-0935D8B62540} URL = http://www.alza.cz/SearchAdvanced.asp?EXPS={searchTerms}
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {206BE1CD-D8E5-4E8B-82A6-7642EF131402} URL = http://search.yahoo.com/search?fr=chr-g ... earchTerms}
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {261F48F8-D058-48FB-AF2F-1612D1198CC3} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {4B2BCD33-D984-4D8E-9C54-B803E34B1CA9} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {593B6F83-B0BB-4B83-A5D9-7AC258B674B2} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {9249FFDB-058C-45D6-9AF3-F1B23BF48FF0} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {9FF53AE7-AE60-4664-949F-033A0F77247D} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {A11803E2-62F5-4A23-B930-9F8D435E2A78} URL = http://www.firmy.cz/phr/{searchTerms}?s ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {A3A70049-68EA-44AC-905D-25C4A57E654C} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {C7C7B0ED-D00A-4989-9D5A-29377FA141AF} URL = http://cs.wikipedia.org/w/index.php?tit ... earchTerms}
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {D55EDDC6-DF84-4DE3-A258-8E0FC1DAE671} URL = http://www.radirna.cz/search/{searchTerms}/
SearchScopes: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> {DCEBF011-A869-4BF6-AF25-376F5EE21962} URL = http://cs.wikipedia.org/w/index.php?tit ... earchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: DownloadHelper Class -> {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} -> C:\Program Files\Common Files\Download Helper\DownloadHelperx64.dll (IE Download Helper)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
BHO-x32: iSkysoft Video Converter Ultimate 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\PROGRA~3\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll No File
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DownloadHelper Class -> {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} -> C:\Program Files (x86)\Common Files\Download Helper\DownloadHelper.dll (IE Download Helper)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus)
Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll (LastPass)
Toolbar: HKLM-x32 - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
Toolbar: HKLM-x32 - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
DPF: HKLM-x32 {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://www.asus.com/support/asusTek_sys_ctrl3.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{E557249B-EC4D-4E00-9A90-D94FCB0F2C10}: [NameServer] 156.154.70.25,156.154.71.25

FireFox:
========
FF ProfilePath: C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244
FF SelectedSearchEngine: Seznam
FF Homepage: https://www.seznam.cz/?logged=1
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @Skype Technologies S.A..com/Skype Web Plugin -> C:\Program Files (x86)\SkypeWebPlugin\npSkypeWebPlugin64.dll (Skype)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.7 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @exent.com/npExentCtl,version=7.0.0.0 -> C:\Program Files (x86)\Free Ride Games\npExentCtl.dll No File
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll (Oberon-Media )
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: www.exent.com/GameTreatWidget -> C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll No File
FF Plugin HKU\S-1-5-21-841361005-909514878-2309378359-1002: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin HKU\S-1-5-21-841361005-909514878-2309378359-1002: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Ruda\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-841361005-909514878-2309378359-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Ruda\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-841361005-909514878-2309378359-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Ruda\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Extension: LastPass - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\Extensions\support@lastpass.com [2015-01-02]
FF Extension: S3.Google Translator - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\Extensions\s3google@translator.xpi [2014-10-17]
FF Extension: Speed Dial - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi [2014-10-17]
FF Extension: Adblock Plus - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-20]
FF Extension: Tab Mix Plus - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2014-10-17]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-04]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-12-04]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [fmconverter@gmail.com] - C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/?gws_rd=cr,ssl&ei=L8ysUuaeEYiXtQayz4GgCQ
CHR StartupUrls: Default -> "hxxp://www.google.cz/?gws_rd=cr,ssl&ei=L8ysUuaeEYiXtQayz4GgCQ"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.5.671\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Picasa) - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (NPLastPass) - C:\Program Files (x86)\LastPass\nplastpass.dll (LastPass)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Ruda\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Google Update) - C:\Users\Ruda\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll No File
CHR Profile: C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Tlumočník pro všechny jazyky) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\amdeidgbmcliegnpcbbkhlflkbdpomhk [2014-03-29]
CHR Extension: (Dokumenty Google) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-29]
CHR Extension: (Greeting Card Maker) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\benkgplfnlmgnpooclhbngibhmconcnn [2014-03-29]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2014-07-23]
CHR Extension: (YouTube) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-27]
CHR Extension: (TV) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\bppbpeijolfcampacpljolaegibfhjph [2014-03-29]
CHR Extension: (Vyhledávání Google) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-29]
CHR Extension: (AdBlock Premium) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2014-03-29]
CHR Extension: (Facebook for Chrome) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdalhedleemkkdjddjgfjmcnbpejpapp [2014-11-07]
CHR Extension: (How to Whatsapp™ on pc) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gehnjenlljoafdhngpkkbigkoofcnmcg [2014-04-23]
CHR Extension: (converter) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gncebhdkjgopkmaklokjadihihfakeoi [2014-03-29]
CHR Extension: (Mortgage Calculators) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gophjlpndiolpbmkiioffbikoegnnapb [2014-03-29]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2014-03-29]
CHR Extension: (Mapy) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgkgohkhjofgjpcebjdhkjompkabdoaj [2014-03-29]
CHR Extension: (Překladač) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjlihpknefpcggkkbceadkcaapkkjikh [2014-06-27]
CHR Extension: (Speed Test) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2014-11-09]
CHR Extension: (Speed Dial 3™(APP)) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfhiehdjpogpbdcicjnphklppinghjj [2014-11-09]
CHR Extension: (Seesmic) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikhnbijacmpeikpnoeddepkehmcofgbh [2014-03-29]
CHR Extension: (Business Card Maker) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\jllleebddagfipdaphlahknlfipmnehj [2014-03-29]
CHR Extension: (Kalkulacka) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdkgihpbaofhkiliohfepioflkkbapao [2014-03-29]
CHR Extension: (Online Hry Zdarma) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfalblilehghcdahejnnejepagmccbib [2014-03-29]
CHR Extension: (Webmaster & SEO Tools) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfnkfoehpejigjhhjffdhmjpdkofcpmi [2014-03-29]
CHR Extension: (Cooking Recipes) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\leakjfgpfppjkjmbmbnpmjeandfnhncm [2014-03-29]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-16]
CHR Extension: (News and Pictures) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfkkkggciojbhfhehfaodadkoheomhbc [2014-03-29]
CHR Extension: (Hledání pracovních nabídek) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgehfboljmhjbmmjhgbakmoocikpkeid [2014-03-29]
CHR Extension: (Sudoku) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\niimgmcbadjegppgegomiappmhoegaih [2014-12-17]
CHR Extension: (Peněženka Google) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Travel Math) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofpimeaclblbaodahnhhmlblagijlnad [2014-03-29]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-03-29]
CHR Extension: (Picasa) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2014-03-29]
CHR Extension: (Click&Clean App) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-03-29]
CHR Extension: (Outlook.com) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2014-03-29]
CHR Extension: (Online Televize) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\picldhpkcgmgfnmombladhakcganoghd [2014-03-29]
CHR Extension: (Gmail) - C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-27]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Ruda\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Linguarde\wcxChrome.crx [Not Found]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70864 2014-12-25] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [7618952 2014-12-09] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265304 2014-12-09] (COMODO)
R2 CPMService; C:\Program Files\COMODO\COMODO Programs Manager\CPMService.exe [116032 2015-01-08] ()
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2370240 2014-11-27] (Comodo Security Solutions, Inc.)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2014-12-25] (Comodo Security Solutions, Inc.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2000-01-01] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [9216 2009-07-14] (Microsoft Corporation)
R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [12907520 2013-02-01] () [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
R2 simptcp; C:\Windows\SysWOW64\tcpsvcs.exe [9216 2009-07-14] (Microsoft Corporation)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-20] (Microsoft Corporation)
R2 SNMP; C:\Windows\SysWOW64\snmp.exe [47616 2010-11-20] (Microsoft Corporation)
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [2324216 2013-11-01] (PS Media s.r.o.)
S3 SystemExplorerHelpService; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [820960 2014-12-20] (Mister Group)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2015-01-03] (TeamViewer GmbH)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27768 2000-01-01] (VIA Technologies, Inc.)
R2 VideoAcceleratorService; C:\Program Files (x86)\SpeedBit Video Accelerator\VideoAcceleratorService.exe [298152 2014-02-24] (SPEEDbit)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [453120 2010-11-20] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [327296 2012-05-31] (Atheros)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2012-02-29] (ASUSTek Computer Inc.)
R3 anvsnddrv; C:\Windows\System32\drivers\anvsnddrv.sys [33872 2015-01-06] (AnvSoft Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 AsusVBus; C:\Windows\System32\DRIVERS\AsusVBus.sys [35968 2012-04-12] (Windows (R) Win 7 DDK provider)
R3 AsusVTouch; C:\Windows\System32\DRIVERS\AsusVTouch.sys [16512 2012-04-12] (Windows (R) Win 7 DDK provider)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [37976 2014-06-26] (Windows (R) Win 7 DDK provider) [File not signed]
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20184 2014-12-09] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [792648 2014-12-09] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2014-12-09] (COMODO)
R0 cumon; C:\Windows\System32\drivers\cumon.sys [205512 2011-09-05] (Windows (R) Win 7 DDK provider)
R0 Evdd; C:\Windows\System32\drivers\evdd.sys [19568 2011-09-05] ()
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2014-12-09] (COMODO)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [164864 2014-10-22] (ITE ) [File not signed]
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 L1C; C:\Windows\System32\DRIVERS\L1C62x64.sys [117912 2000-01-01] (Qualcomm Atheros Co., Ltd.)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2000-01-01] (Intel Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [189440 2009-07-14] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 PCWinSoft; C:\Windows\System32\DRIVERS\scrcamhrdrv_x64.sys [241800 2012-10-11] (Windows (R) Server 2003 DDK provider)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [16152 2014-12-22] ()
S3 XHCIdrv; C:\Windows\System32\DRIVERS\XHCIdrv.sys [119720 2013-08-08] (Windows (R) Win 7 DDK provider)
S3 CLVirtualBus01; system32\DRIVERS\CLVirtualBus01.sys [X]
S3 dcdbas; system32\DRIVERS\dcdbas64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S1 KDHacker; \??\c:\program files (x86)\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 MsgPlusDriver; system32\DRIVERS\MsgPlusDriver.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-09 23:53 - 2015-01-09 23:53 - 00000000 ___RD () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-01-09 23:20 - 2015-01-10 00:11 - 00000000 ____D () C:\FRST
2015-01-09 18:43 - 2015-01-09 18:43 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\VitySoft
2015-01-09 11:39 - 2015-01-09 11:39 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\WinRAR
2015-01-09 11:24 - 2015-01-09 11:25 - 01444352 _____ () C:\Users\Ruda\Downloads\7z922-x64.msi
2015-01-09 11:09 - 2015-01-09 11:09 - 00000871 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2015-01-09 11:09 - 2015-01-09 11:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2015-01-09 11:09 - 2015-01-09 11:09 - 00000000 ____D () C:\Program Files\CPUID
2015-01-09 11:08 - 2015-01-09 11:08 - 01577464 _____ ( ) C:\Users\Ruda\Downloads\cpu-z_1.71.1-setup-en.exe
2015-01-08 18:16 - 2015-01-08 18:16 - 00372576 _____ () C:\Users\Ruda\Downloads\SoftonicDownloader_for_ashampoo-hdd-control.exe
2015-01-08 18:11 - 2011-09-05 16:12 - 00027968 _____ (COMODO Security Solutions Inc.) C:\Windows\system32\cpmnat.exe
2015-01-08 18:10 - 2015-01-09 11:45 - 00244224 ___SH () C:\Users\Ruda\Downloads\Thumbs.db
2015-01-08 17:58 - 2015-01-08 17:58 - 00001017 _____ () C:\Users\Public\Desktop\COMODO Programs Manager.lnk
2015-01-08 17:58 - 2011-09-05 16:14 - 00205512 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\cumon.sys
2015-01-08 17:58 - 2011-09-05 16:14 - 00019568 _____ () C:\Windows\system32\Drivers\evdd.sys
2015-01-08 17:44 - 2015-01-08 17:44 - 11278928 _____ (COMODO) C:\Users\Ruda\Downloads\CPM_SETUP_1.3.2.30_xp_vista_server2003_win7.exe
2015-01-07 20:00 - 2015-01-07 20:00 - 00000000 ____D () C:\Users\Ruda\Documents\iSkysoft Video Converter Ultimate
2015-01-07 20:00 - 2015-01-07 20:00 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
2015-01-07 20:00 - 2015-01-07 20:00 - 00000000 ____D () C:\Users\Ruda\AppData\Local\iSkysoft
2015-01-07 19:59 - 2015-01-07 20:08 - 00000000 ____D () C:\ProgramData\iSkysoft
2015-01-07 19:59 - 2015-01-07 20:06 - 00000000 ____D () C:\ProgramData\iSkysoft Video Converter Ultimate
2015-01-07 19:58 - 2015-01-07 19:58 - 00000000 ____D () C:\Users\Public\Documents\iSkysoft
2015-01-07 02:59 - 2015-01-07 03:48 - 00001148 _____ () C:\Users\Public\Desktop\Ashampoo Snap 7.lnk
2015-01-07 02:57 - 2015-01-07 02:57 - 32401408 _____ (Ashampoo GmbH & Co. KG ) C:\Users\Ruda\Downloads\ashampoo_snap_7_e7.0.10_sm.exe
2015-01-07 02:39 - 2015-01-09 23:50 - 00001680 _____ () C:\Windows\setupact.log
2015-01-07 02:39 - 2015-01-07 02:39 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-07 02:38 - 2015-01-09 23:50 - 00004678 _____ () C:\Windows\PFRO.log
2015-01-06 17:01 - 2015-01-09 18:51 - 00318464 ___SH () C:\Users\Ruda\Documents\Thumbs.db
2015-01-06 15:10 - 2015-01-06 15:10 - 00000000 ____D () C:\Users\Ruda\Documents\Any Video Converter Ultimate
2015-01-06 15:05 - 2015-01-06 15:05 - 00033872 _____ (AnvSoft Inc.) C:\Windows\system32\Drivers\anvsnddrv.sys
2015-01-06 14:58 - 2015-01-06 14:59 - 37459872 _____ (Any-Video-Converter.com ) C:\Users\Ruda\Downloads\avc-ultimate.exe
2015-01-06 01:38 - 2015-01-06 01:38 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Avg
2015-01-06 01:37 - 2015-01-08 17:47 - 00000000 ____D () C:\ProgramData\AVG
2015-01-06 01:13 - 2015-01-06 19:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft
2015-01-06 01:12 - 2015-01-06 19:55 - 00000000 ____D () C:\Program Files (x86)\Anvsoft
2015-01-04 15:22 - 2015-01-04 15:34 - 00000000 ____D () C:\Users\Ruda\Documents\Pračka Whi 55510
2015-01-03 21:44 - 2015-01-03 21:44 - 00000000 ____D () C:\Users\Ruda\AppData\Local\TeamViewer
2015-01-03 20:35 - 2015-01-03 20:35 - 00001009 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-01-03 20:35 - 2015-01-03 20:35 - 00000997 _____ () C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-01-03 20:35 - 2015-01-03 20:35 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-01-03 20:34 - 2015-01-03 20:34 - 08986784 _____ (TeamViewer GmbH) C:\Users\Ruda\Downloads\TeamViewer_Setup.exe
2015-01-03 12:02 - 2015-01-08 22:45 - 24743106 _____ () C:\Users\Ruda\Downloads\vlc-2.1.5-win32.exe
2015-01-02 01:13 - 2015-01-02 01:13 - 00000000 ___RD () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2015-01-02 01:10 - 2015-01-09 23:50 - 00027142 _____ () C:\Windows\CUAppUsage.Dat
2015-01-01 22:37 - 2015-01-08 17:45 - 629145600 ____H () C:\fileimage.dat
2014-12-31 12:24 - 2014-12-31 12:24 - 00034304 _____ (mst software GmbH, Germany) C:\Windows\system32\DfSdkBt.exe
2014-12-31 12:24 - 2014-12-31 12:24 - 00028160 _____ (mst software GmbH, Germany) C:\Windows\SysWOW64\DfSdkBt32.exe
2014-12-31 12:24 - 2014-12-31 12:24 - 00001442 _____ () C:\Users\Public\Desktop\1-click Optimizer.lnk
2014-12-31 12:24 - 2014-12-31 12:24 - 00001214 _____ () C:\Users\Public\Desktop\Ashampoo WinOptimizer Free.lnk
2014-12-30 02:32 - 2014-12-30 02:32 - 00001117 _____ () C:\Users\Public\Desktop\CDBurnerXP.lnk
2014-12-30 02:32 - 2014-12-30 02:32 - 00001069 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
2014-12-30 02:32 - 2014-12-30 02:32 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Canneverbe Limited
2014-12-30 02:32 - 2014-12-30 02:32 - 00000000 ____D () C:\Program Files (x86)\CDBurnerXP
2014-12-30 02:25 - 2014-12-30 02:26 - 00000000 ____D () C:\Program Files (x86)\Q-Dir
2014-12-30 02:25 - 2014-12-30 02:25 - 00003130 _____ () C:\Windows\System32\Tasks\{737437BC-901B-4288-BABE-7F80E77DBB3F}
2014-12-30 02:24 - 2014-12-30 02:24 - 00758272 _____ (Nenad Hrg (SoftwareOK.com)) C:\Users\Ruda\Downloads\Q-Dir_Installer.exe
2014-12-30 02:20 - 2014-12-30 02:21 - 05641056 _____ (Canneverbe Limited ) C:\Users\Ruda\Downloads\cdbxp_setup_4.5.4.5306.exe
2014-12-28 20:04 - 2014-12-28 20:04 - 00000006 _____ () C:\Users\Ruda\AppData\Roaming\Network Meter_Usage.ini
2014-12-28 03:28 - 2015-01-10 00:10 - 01444856 _____ () C:\Windows\system32\Drivers\fvstore.dat
2014-12-28 02:53 - 2014-12-28 02:53 - 00000891 _____ () C:\Users\Ruda-PC-2\Desktop\Plus500.lnk
2014-12-28 01:31 - 2014-12-28 01:31 - 00000000 ____D () C:\Users\Ruda\Documents\Ashampoo Burning Studio FREE
2014-12-27 20:56 - 2015-01-08 17:33 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\IHlpr
2014-12-27 16:23 - 2014-12-27 16:23 - 00002011 _____ () C:\Users\Ruda-PC-2\Desktop\FastImageResizer.lnk
2014-12-27 16:23 - 2014-12-27 16:23 - 00002011 _____ () C:\Users\Ruda\Desktop\FastImageResizer.lnk
2014-12-27 16:23 - 2014-12-27 16:23 - 00002011 _____ () C:\Users\Guest\Desktop\FastImageResizer.lnk
2014-12-27 00:58 - 2014-12-27 00:58 - 00000000 ____D () C:\Free Rapid
2014-12-27 00:32 - 2014-12-27 00:32 - 02173952 _____ () C:\Users\Ruda\Downloads\adwcleaner_4.106.exe
2014-12-26 23:41 - 2014-12-26 23:41 - 00000000 ____D () C:\ProgramData\PCB_Win7_
2014-12-26 21:42 - 2014-12-26 21:42 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2014-12-25 14:40 - 2015-01-10 00:10 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat
2014-12-25 14:40 - 2015-01-02 01:10 - 00000000 ____D () C:\Windows\System32\Tasks\COMODO
2014-12-25 14:40 - 2014-12-25 14:40 - 00001888 _____ () C:\Users\Public\Desktop\COMODO Internet Security.lnk
2014-12-25 14:36 - 2014-12-25 14:38 - 00000000 ____D () C:\Program Files\COMODO
2014-12-25 14:35 - 2015-01-08 17:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2014-12-25 14:35 - 2014-12-25 14:35 - 00057096 _____ (COMODO CA Limited) C:\Windows\system32\certsentry.dll
2014-12-25 14:35 - 2014-12-25 14:35 - 00048392 _____ (COMODO CA Limited) C:\Windows\SysWOW64\certsentry.dll
2014-12-25 14:35 - 2014-12-25 14:35 - 00001078 _____ () C:\Users\Public\Desktop\Comodo Dragon.lnk
2014-12-25 14:35 - 2014-12-25 14:35 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Comodo
2014-12-25 14:35 - 2014-12-25 14:35 - 00000000 ____D () C:\ProgramData\Comodo Downloader
2014-12-25 14:35 - 2014-12-25 14:35 - 00000000 ____D () C:\Program Files (x86)\Comodo
2014-12-25 14:33 - 2014-12-25 14:40 - 00000000 ____D () C:\ProgramData\Comodo
2014-12-25 13:31 - 2014-12-25 13:33 - 226075384 _____ (COMODO) C:\Users\Ruda\Downloads\cispremium_installer_6100_08.exe
2014-12-24 21:47 - 2014-12-24 21:47 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\MediaInfo
2014-12-24 18:03 - 2014-12-24 18:03 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2014-12-24 15:21 - 2014-12-24 15:21 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET
2014-12-24 12:34 - 2014-12-24 12:34 - 00000000 ____D () C:\Windows\SysWOW64\NV
2014-12-24 12:34 - 2014-12-24 12:34 - 00000000 ____D () C:\Windows\system32\NV
2014-12-24 12:29 - 2014-12-13 11:08 - 32099472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 25460552 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 24764232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 20465808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 18594432 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 17264312 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 16040184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 13288360 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 13202520 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 10770120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 10710160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 10345280 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-12-24 12:29 - 2014-12-13 11:08 - 03610440 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 03248968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 02897824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 01895056 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434709.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 01556624 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434709.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00994384 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00968336 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00942400 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00928072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00906560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00353224 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00306328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00178632 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-12-24 12:29 - 2014-12-13 11:08 - 00031376 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2014-12-24 12:29 - 2014-12-13 11:08 - 00027983 _____ () C:\Windows\system32\nvinfo.pb
2014-12-24 11:55 - 2014-11-22 11:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-12-24 11:55 - 2014-11-22 11:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-12-24 04:41 - 2014-12-24 04:41 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\Macromedia
2014-12-24 04:10 - 2014-12-24 04:10 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\ASUS WebStorage
2014-12-24 03:52 - 2014-12-24 03:52 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\Mozilla
2014-12-24 03:52 - 2014-12-24 03:52 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\Mozilla
2014-12-24 03:51 - 2015-01-05 00:14 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\LogMeIn Hamachi
2014-12-24 03:51 - 2014-12-24 03:51 - 00077872 _____ () C:\Users\Ruda-PC-2\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-24 03:51 - 2014-12-24 03:51 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\NVIDIA Corporation
2014-12-24 03:51 - 2014-12-24 03:51 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\LogMeIn
2014-12-24 03:50 - 2015-01-02 01:13 - 00000387 _____ () C:\Users\Ruda-PC-2\AppData\Roaming\sp_data.sys
2014-12-24 03:50 - 2014-12-24 04:40 - 00000000 ____D () C:\Users\Ruda-PC-2\Documents\Bluetooth Folder
2014-12-24 03:50 - 2014-12-24 03:50 - 00001395 _____ () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\LastPass
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\Atheros
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\Adobe
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\NVIDIA
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\BMExplorer
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\Adobe
2014-12-24 03:50 - 2014-12-24 03:50 - 00000000 _____ () C:\Users\Ruda-PC-2\agent.log
2014-12-24 03:49 - 2015-01-09 17:59 - 00000000 ____D () C:\Users\Ruda-PC-2
2014-12-24 03:49 - 2014-12-24 03:50 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\Google
2014-12-24 03:49 - 2014-12-24 03:49 - 00000020 ___SH () C:\Users\Ruda-PC-2\ntuser.ini
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Šablony
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Soubory cookie
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Poslední
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Okolní tiskárny
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Okolní síť
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Nabídka Start
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Dokumenty
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Documents\Obrázky
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Documents\Hudba
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Documents\Filmy
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\Data aplikací
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 _SHDL () C:\Users\Ruda-PC-2\AppData\Local\Data aplikací
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\VirtualStore
2014-12-24 03:49 - 2014-12-24 03:49 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Local\ASUS
2014-12-24 03:49 - 2013-12-07 14:41 - 00000000 ____D () C:\Users\Ruda-PC-2\AppData\Roaming\Macromedia
2014-12-24 03:49 - 2013-03-07 03:49 - 00002126 _____ () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
2014-12-24 03:49 - 2009-07-14 05:54 - 00000000 ___RD () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-24 03:49 - 2009-07-14 05:49 - 00000000 ___RD () C:\Users\Ruda-PC-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-12-24 02:15 - 2014-12-24 02:15 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Oberon Games
2014-12-24 02:11 - 2014-12-24 02:11 - 00000000 ____D () C:\ProgramData\Oberon Games
2014-12-23 22:55 - 2014-12-23 22:55 - 00003170 _____ () C:\Windows\System32\Tasks\{F54D05B9-8665-451C-B33E-50DBCEE2C466}
2014-12-23 22:31 - 2014-12-23 22:31 - 00001802 _____ () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeRapid 0.9u4.lnk
2014-12-23 22:23 - 2015-01-03 02:43 - 00000000 ____D () C:\Users\Ruda\Downloads\FreeRapid-0.9u4
2014-12-23 22:01 - 2014-12-23 22:01 - 00003076 _____ () C:\Windows\System32\Tasks\{CE160BED-AA6C-4B07-B819-15E1D2ED4F96}
2014-12-23 13:26 - 2014-12-23 13:28 - 00000000 ____D () C:\Users\Ruda\Documents\Evidence LSoft
2014-12-23 13:26 - 2014-12-23 13:26 - 00000937 _____ () C:\Users\Public\Desktop\Evidence LSoft.lnk
2014-12-23 13:26 - 2014-12-23 13:26 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\LSoft
2014-12-23 13:26 - 2014-12-23 13:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evidence LSoft
2014-12-23 13:26 - 2014-12-23 13:26 - 00000000 ____D () C:\Program Files (x86)\LSoft
2014-12-23 12:00 - 2014-12-23 12:00 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Tracker Software
2014-12-23 11:58 - 2015-01-02 01:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Q-Dir
2014-12-23 11:58 - 2014-12-30 02:26 - 00001797 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Q-Dir.lnk
2014-12-23 11:58 - 2014-12-30 02:26 - 00001791 _____ () C:\Users\Public\Desktop\Q-Dir.lnk
2014-12-23 11:57 - 2015-01-02 01:10 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Q-Dir
2014-12-23 02:36 - 2014-12-23 02:36 - 06286448 _____ (Microsoft Corporation) C:\Users\Ruda\Downloads\Silverlight.exe
2014-12-22 17:48 - 2014-12-22 17:48 - 01908840 _____ (Mister Group ) C:\Users\Ruda\Downloads\SystemExplorerSetup_620.exe
2014-12-22 03:06 - 2014-12-22 03:07 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.3
2014-12-22 03:06 - 2014-12-22 03:06 - 00001468 _____ () C:\Users\Public\Desktop\LibreOffice 4.3.lnk
2014-12-22 02:56 - 2014-12-22 02:57 - 225890304 _____ () C:\Users\Ruda\Downloads\LibreOffice_4.3.5_Win_x86.msi
2014-12-22 02:44 - 2015-01-02 01:11 - 00000000 ____D () C:\Program Files\Q-Dir
2014-12-22 02:44 - 2014-12-22 02:44 - 00000000 ____D () C:\Users\Ruda\Documents\Favorites_Q_Dir
2014-12-21 14:45 - 2014-12-21 15:13 - 00000000 ____D () C:\Users\Ruda\Documents\žárovky
2014-12-20 11:12 - 2014-12-20 11:12 - 00008192 ____H () C:\Users\Ruda\Downloads\photothumb.db
2014-12-20 00:18 - 2014-12-20 00:18 - 00011987 _____ () C:\Users\Ruda\Downloads\OutlookContacts.csv
2014-12-19 22:10 - 2015-01-07 22:52 - 00000000 ____D () C:\Users\Ruda\Documents\LICENČNÍ ČÍSLA PROGR
2014-12-18 22:44 - 2014-12-18 22:44 - 05317104 _____ (Piriform Ltd) C:\Users\Ruda\Downloads\ccsetup501.exe
2014-12-18 00:50 - 2014-12-18 00:50 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Facebook
2014-12-17 22:54 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-17 22:54 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 18:56 - 2014-12-17 18:56 - 00001259 _____ () C:\Users\Public\Desktop\Ashampoo Internet Accelerator 3.lnk
2014-12-17 14:29 - 2014-12-17 14:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-12-17 12:50 - 2014-12-17 12:52 - 00000000 ____D () C:\Users\Ruda\Documents\Freemake
2014-12-17 12:50 - 2014-12-17 12:50 - 00001312 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2014-12-17 12:50 - 2014-12-17 12:50 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2014-12-17 12:50 - 2014-12-17 12:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2014-12-17 12:49 - 2014-12-17 12:50 - 00000000 ____D () C:\Program Files (x86)\Freemake
2014-12-17 12:46 - 2014-12-17 12:46 - 07389641 _____ () C:\Users\Ruda\Downloads\FreemakeVideoConverter-setup.exe
2014-12-16 22:52 - 2014-12-16 22:52 - 00002119 _____ () C:\Users\Ruda\AppData\Local\recently-used.xbel
2014-12-16 22:29 - 2014-12-16 22:29 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\FileOpen
2014-12-16 22:29 - 2014-12-16 22:29 - 00000000 ____D () C:\ProgramData\FileOpen
2014-12-16 22:26 - 2014-12-16 22:26 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Downloaded Installations
2014-12-16 17:05 - 2014-12-16 17:05 - 00000000 ____D () C:\Program Files (x86)\Flock
2014-12-15 16:28 - 2014-12-15 16:28 - 00000953 _____ () C:\Users\Public\Desktop\PicPick.lnk
2014-12-15 16:28 - 2014-12-15 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PicPick
2014-12-15 16:28 - 2014-12-15 16:28 - 00000000 ____D () C:\Program Files (x86)\PicPick
2014-12-13 12:10 - 2014-12-13 13:25 - 00000000 ____D () C:\ProgramData\SendMails
2014-12-12 11:29 - 2014-12-13 12:10 - 00000000 ____D () C:\Users\Ruda\Downloads\ADOBE
2014-12-11 23:27 - 2014-12-11 23:27 - 00000000 ____D () C:\Users\Ruda\Documents\FormatFactory
2014-12-11 19:47 - 2014-12-12 01:39 - 00000000 ____D () C:\Program Files\MediaCoder
2014-12-11 18:13 - 2014-12-11 22:58 - 00000000 ____D () C:\Users\Ruda\Documents\ConvertXToDVD
2014-12-11 18:11 - 2015-01-01 13:54 - 00001057 _____ () C:\Users\Ruda\AppData\Roaming\vso_ts_preview.xml
2014-12-11 10:36 - 2014-12-11 10:46 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KitePlayer
2014-12-11 02:15 - 2014-12-11 02:17 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-12-11 02:14 - 2014-12-11 02:15 - 00000000 ____D () C:\Program Files (x86)\iplay_en

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-01-09 23:59 - 2009-07-14 05:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-09 23:59 - 2009-07-14 05:45 - 00018736 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-09 23:57 - 2014-10-19 14:45 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job
2015-01-09 23:55 - 2013-05-29 00:14 - 01799297 _____ () C:\Windows\WindowsUpdate.log
2015-01-09 23:53 - 2013-07-15 19:59 - 00000000 ____D () C:\Users\Ruda\AppData\Local\LogMeIn Hamachi
2015-01-09 23:53 - 2013-03-07 02:52 - 00000466 _____ () C:\Users\Ruda\AppData\Roaming\sp_data.sys
2015-01-09 23:52 - 2013-11-03 13:54 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 23:51 - 2014-10-20 19:27 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-09 23:51 - 2014-04-13 15:39 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-01-09 23:50 - 2014-09-14 12:37 - 00000000 _____ () C:\Windows\SysWOW64\sinstall.log
2015-01-09 23:50 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-09 23:39 - 2014-07-03 21:04 - 00000000 ___DC () C:\AdwCleaner
2015-01-09 23:38 - 2014-10-20 19:27 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-09 21:55 - 2014-09-30 19:27 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job
2015-01-09 21:53 - 2014-11-23 03:32 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Ashampoo Photo Commander 11
2015-01-09 21:53 - 2014-01-10 00:12 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Ashampoo
2015-01-09 20:59 - 2013-11-26 11:40 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2015-01-09 19:57 - 2014-10-19 14:45 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-09 18:47 - 2013-11-23 00:33 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\vlc
2015-01-09 18:11 - 2013-03-07 02:48 - 00000000 ____D () C:\Users\Ruda
2015-01-09 17:59 - 2014-01-05 15:51 - 00000000 ____D () C:\Users\Guest
2015-01-09 17:59 - 2013-12-07 18:51 - 00000000 ____D () C:\Users\Classic .NET AppPool
2015-01-09 17:59 - 2013-07-28 10:32 - 00000000 ____D () C:\Users\DefaultAppPool
2015-01-09 17:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2015-01-09 17:48 - 2013-03-07 02:52 - 00000000 ____D () C:\Users\Ruda\Documents\Bluetooth Folder
2015-01-09 17:42 - 2013-08-23 16:09 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Skype
2015-01-09 15:01 - 2014-12-05 01:15 - 00000272 _____ () C:\Windows\Tasks\_DEFAULT.job
2015-01-09 00:55 - 2014-09-30 19:27 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-08 23:00 - 2013-11-03 13:54 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-08 23:00 - 2013-11-03 13:54 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-08 23:00 - 2013-11-03 13:54 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-08 22:46 - 2013-12-29 19:08 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-01-08 19:23 - 2014-06-12 12:45 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\QuickScan
2015-01-08 18:58 - 2014-01-10 00:11 - 00000000 ____D () C:\ProgramData\Ashampoo
2015-01-08 18:54 - 2014-04-22 08:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2015-01-08 18:54 - 2014-04-22 08:49 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2015-01-08 17:37 - 2013-11-14 11:57 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\FastStone
2015-01-08 17:33 - 2014-07-28 00:16 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\AnvSoft
2015-01-08 15:01 - 2011-02-19 06:36 - 00840382 _____ () C:\Windows\system32\perfh005.dat
2015-01-08 15:01 - 2011-02-19 06:36 - 00232846 _____ () C:\Windows\system32\perfc005.dat
2015-01-08 15:01 - 2009-07-14 06:13 - 01943482 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-07 23:15 - 2013-10-02 17:41 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\uTorrent
2015-01-07 17:20 - 2014-09-01 16:37 - 00000000 ____D () C:\Users\Ruda\TapinRadio
2015-01-07 16:07 - 2014-10-07 00:16 - 00009728 _____ () C:\Users\Ruda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-07 01:49 - 2013-05-31 09:15 - 00000000 ____D () C:\Program Files\Recuva
2015-01-07 01:45 - 2013-03-07 10:49 - 00000000 ____D () C:\Users\Ruda\AppData\Local\CrashDumps
2015-01-07 01:15 - 2014-12-05 01:15 - 00000280 _____ () C:\Windows\Tasks\_UPDATES.job
2015-01-05 21:58 - 2013-03-07 03:23 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Adobe
2015-01-05 00:21 - 2014-05-15 13:38 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\TeamViewer
2015-01-04 23:43 - 2014-09-12 22:45 - 00000452 _____ () C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job
2015-01-04 22:30 - 2014-05-08 20:46 - 00000000 ____D () C:\Users\Ruda\Downloads\Návody
2015-01-04 21:11 - 2014-10-30 12:31 - 00000701 _____ () C:\Users\Ruda\.swfinfo
2015-01-04 12:52 - 2009-07-14 05:45 - 04906320 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-04 02:32 - 2012-02-24 12:40 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-03 21:42 - 2014-09-13 00:22 - 00077872 _____ () C:\Users\Ruda\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-03 12:05 - 2014-06-19 14:40 - 00000000 ____D () C:\Program Files (x86)\Recepty doma
2015-01-02 02:46 - 2013-12-02 11:38 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-02 01:09 - 2014-06-29 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.3
2015-01-02 01:09 - 2014-06-29 17:00 - 00000000 ____D () C:\Program Files (x86)\Cheat Engine 6.3
2015-01-02 01:08 - 2013-10-10 09:54 - 00000000 __HDC () C:\VTRoot
2015-01-01 14:06 - 2014-11-11 16:20 - 00000000 ____D () C:\ProgramData\VSO
2015-01-01 14:05 - 2014-03-24 18:03 - 00099384 _____ () C:\Users\Ruda\AppData\Roaming\inst.exe
2015-01-01 14:05 - 2014-03-24 18:03 - 00082816 _____ (VSO Software) C:\Users\Ruda\AppData\Roaming\pcouffin.sys
2015-01-01 14:05 - 2014-03-24 18:03 - 00007859 _____ () C:\Users\Ruda\AppData\Roaming\pcouffin.cat
2015-01-01 14:05 - 2014-03-24 18:03 - 00000033 _____ () C:\Users\Ruda\AppData\Roaming\pcouffin.log
2014-12-31 22:15 - 2014-11-29 21:39 - 00000000 ____D () C:\Users\Ruda\Documents\DAROVACÍ SMLOUVA
2014-12-31 22:15 - 2014-11-29 21:11 - 00000000 ____D () C:\Users\Ruda\Downloads\images
2014-12-31 22:15 - 2014-11-28 01:50 - 00000000 ____D () C:\Users\Ruda\Documents\čištění
2014-12-31 22:15 - 2014-09-29 13:46 - 00000000 ____D () C:\Users\Ruda\Downloads\Photos
2014-12-30 11:24 - 2014-06-19 14:40 - 00201216 _____ () C:\Windows\SysWOW64\mediarcpt.dll
2014-12-30 11:24 - 2014-06-19 14:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recepty doma
2014-12-30 11:23 - 2014-10-22 22:49 - 10056656 _____ (Martin Roubec ) C:\Users\Ruda\Downloads\InstalRecepty.exe
2014-12-30 02:26 - 2013-09-03 09:22 - 00070130 _____ () C:\Windows\Q-Dir.ini
2014-12-28 21:14 - 2014-11-04 12:14 - 00001020 _____ () C:\Users\Public\Desktop\PDF-Viewer.lnk
2014-12-28 21:14 - 2014-11-04 12:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
2014-12-28 21:14 - 2014-11-04 12:14 - 00000000 ____D () C:\Program Files\Tracker Software
2014-12-28 20:47 - 2013-07-19 14:37 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Oberon Games
2014-12-28 20:47 - 2012-02-24 12:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Park
2014-12-28 20:45 - 2013-03-08 02:36 - 00000000 ____D () C:\ProgramData\Temp
2014-12-28 02:53 - 2014-11-05 01:12 - 00000891 _____ () C:\Users\Ruda\Desktop\Plus500.lnk
2014-12-28 02:53 - 2014-11-05 01:12 - 00000891 _____ () C:\Users\Guest\Desktop\Plus500.lnk
2014-12-28 02:30 - 2013-07-24 16:02 - 00034816 _____ (Elaborate Bytes AG) C:\Windows\system32\Drivers\VClone.sys
2014-12-26 17:59 - 2014-11-30 11:45 - 00000624 _____ () C:\Users\Ruda\AppData\Roaming\All CPU MeterV3_Settings.ini
2014-12-26 01:48 - 2013-03-07 11:47 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-12-24 12:34 - 2014-11-28 01:08 - 00000000 ___DC () C:\Temp
2014-12-24 12:34 - 2013-03-08 11:06 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-12-24 03:50 - 2014-01-05 15:52 - 00001547 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-12-24 03:50 - 2013-03-08 11:22 - 00000000 ____D () C:\ProgramData\Atheros
2014-12-24 01:25 - 2014-02-11 11:06 - 00000000 ____D () C:\Users\Ruda\AppData\Local\SlimWare Utilities Inc
2014-12-23 22:01 - 2014-11-18 01:24 - 00419840 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-12-23 22:01 - 2014-11-18 01:24 - 00413696 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll
2014-12-23 22:01 - 2014-11-18 01:24 - 00133632 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-12-23 22:01 - 2014-11-18 01:24 - 00110592 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
2014-12-23 11:37 - 2013-04-07 16:45 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\PhotoScape
2014-12-23 11:30 - 2014-06-08 17:53 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-23 10:21 - 2014-03-25 01:22 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-12-22 17:49 - 2014-05-05 00:52 - 00001054 _____ () C:\Users\Public\Desktop\System Explorer.lnk
2014-12-22 17:49 - 2014-05-05 00:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Explorer
2014-12-22 17:49 - 2014-04-21 13:00 - 00000000 ____D () C:\Program Files (x86)\System Explorer
2014-12-22 03:30 - 2014-02-11 11:06 - 00016152 _____ () C:\Windows\system32\Drivers\SWDUMon.sys
2014-12-22 03:06 - 2014-11-16 17:45 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4
2014-12-20 11:11 - 2014-01-06 02:52 - 00000000 ____D () C:\Users\Ruda\.gimp-2.8
2014-12-20 11:10 - 2014-01-06 02:55 - 00000000 ____D () C:\Users\Ruda\AppData\Local\gtk-2.0
2014-12-20 11:09 - 2014-06-24 13:54 - 00000000 ____D () C:\Users\Ruda\.thumbnails
2014-12-20 00:35 - 2014-02-24 11:28 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-12-20 00:35 - 2013-08-23 15:45 - 00000000 ____D () C:\ProgramData\Skype
2014-12-18 22:45 - 2013-12-02 11:38 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-12-18 00:50 - 2014-02-25 23:03 - 00003898 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA
2014-12-18 00:50 - 2014-02-25 23:03 - 00003530 _____ () C:\Windows\System32\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core
2014-12-17 14:29 - 2013-07-15 19:57 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-12-17 12:51 - 2014-08-07 00:33 - 00000000 ____D () C:\ProgramData\Freemake
2014-12-16 23:43 - 2013-10-27 20:04 - 00000000 ____D () C:\Users\Ruda\Documents\XPS dokumenty
2014-12-15 16:28 - 2014-09-30 10:22 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\PicPick
2014-12-13 11:08 - 2014-11-24 15:50 - 14128496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2014-12-13 11:08 - 2014-10-10 13:39 - 03293136 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2014-12-13 11:08 - 2014-05-27 12:05 - 00876976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-12-13 11:08 - 2013-11-19 19:52 - 00165760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 06859408 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 03513488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 02558608 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 01097360 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 00935240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-12-13 09:03 - 2014-01-08 20:21 - 00386368 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 00075080 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2014-12-13 09:03 - 2014-01-08 20:21 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-12-13 01:12 - 2014-06-02 17:11 - 01715224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-12-13 01:12 - 2014-06-02 17:11 - 01291464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-12-13 01:12 - 2013-10-28 19:05 - 02824504 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12 - 2013-10-28 19:05 - 02210040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2014-12-13 00:11 - 2014-01-08 20:21 - 04151176 _____ () C:\Windows\system32\nvcoproc.bin
2014-12-12 14:00 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 01:41 - 2014-09-28 15:19 - 00002145 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-11 18:09 - 2014-03-24 18:03 - 00082816 _____ (VSO Software) C:\Windows\system32\Drivers\pcouffin.sys
2014-12-11 02:17 - 2013-05-27 11:21 - 00000000 ____D () C:\Program Files (x86)\Oberon Media SIDR
2014-12-11 02:15 - 2013-05-27 11:22 - 00000000 ____D () C:\Users\Ruda\AppData\Roaming\Oberon Media
2014-12-11 01:28 - 2014-11-05 01:11 - 00384488 _____ () C:\Users\Ruda\Downloads\InstallPlus500.exe

Some content of TEMP:
====================
C:\Users\Ruda\AppData\Local\Temp\feedback.dll
C:\Users\Ruda\AppData\Local\Temp\Quarantine.exe
C:\Users\Ruda\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-04 17:46

==================== End Of Log ============================

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#2 Příspěvek od Márty84 »

Zdravim :)


:arrow: Otevrete si poznamkovy blok a zkopirujte do nej tento skript

Kód: Vybrat vše

Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [759712 2014-09-12] (Adobe Systems Incorporated)
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Facebook Update] => C:\Users\Ruda\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-12-18] (Facebook Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> TopResultURLFallback http://search.certified-toolbar.com?si= ... D049FA9&q={searchTerms}
BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
BHO-x32: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
BHO-x32: iSkysoft Video Converter Ultimate 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\PROGRA~3\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll No File
Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
Toolbar: HKLM-x32 - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
Toolbar: HKLM-x32 - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File

CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Ruda\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Linguarde\wcxChrome.crx [Not Found]

S3 dcdbas; system32\DRIVERS\dcdbas64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]

2015-01-06 01:38 - 2015-01-06 01:38 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Avg
2015-01-06 01:37 - 2015-01-08 17:47 - 00000000 ____D () C:\ProgramData\AVG
2015-01-09 23:52 - 2013-11-03 13:54 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 23:51 - 2014-10-20 19:27 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-09 23:38 - 2014-10-20 19:27 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-09 21:55 - 2014-09-30 19:27 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job
2015-01-09 19:57 - 2014-10-19 14:45 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-09 00:55 - 2014-09-30 19:27 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-07 01:15 - 2014-12-05 01:15 - 00000280 _____ () C:\Windows\Tasks\_UPDATES.job
2015-01-09 15:01 - 2014-12-05 01:15 - 00000272 _____ () C:\Windows\Tasks\_DEFAULT.job
2015-01-04 23:43 - 2014-09-12 22:45 - 00000452 _____ () C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job

Hosts:
EmptyTemp:
Reboot:
End
Vlevo nahore kliknete na napis Soubor
Kliknete na napis Ulozit jako...
Napiste spravne ten cerveny nazev fixlist a ulozte na plochu.
Vypnete antivir i dalsi pripadne zabezpeceni.
Spustte FRST jako spravce, kliknete na napis Fix a program vykona prikazy.
Po restartu pc by se mel objevit novy log - s nazvem fixlog, ten mi sem zase zkopirujte.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#3 Příspěvek od rudy630 »

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-01-2015
Ran by Ruda at 2015-01-10 10:17:24 Run:1
Running from C:\PerfLogs\Desktop
Loaded Profile: Ruda (Available profiles: Ruda & Ruda-PC-2 & Guest & Classic .NET AppPool & DefaultAppPool)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Adobe Reader Synchronizer] => C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AdobeCollabSync.exe [759712 2014-09-12] (Adobe Systems Incorporated)
HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Run: [Facebook Update] => C:\Users\Ruda\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-12-18] (Facebook Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> TopResultURLFallback http://search.certified-toolbar.com?si= ... D049FA9&q={searchTerms}
BHO: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
BHO-x32: Iplay Gamesbar -> {7ffa5f54-1c4f-46de-8576-c271a0dd482f} -> C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
BHO-x32: iSkysoft Video Converter Ultimate 5.1.0 -> {AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE} -> C:\PROGRA~3\iSkysoft\Video Converter Ultimate\WSBrowserAppMgr.dll No File
Toolbar: HKLM - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX64.dll ()
Toolbar: HKLM-x32 - No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
Toolbar: HKLM-x32 - Iplay Gamesbar - {7ffa5f54-1c4f-46de-8576-c271a0dd482f} - C:\Program Files (x86)\iplay_en\encyclopediabritannicagamesbarX.dll ()
Toolbar: HKU\S-1-5-21-841361005-909514878-2309378359-1002 -> No Name - {25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} - No File
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
Handler: WSISVCUchrome - {78A543EB-3A61-4ED3 - No File

CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Ruda\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
CHR HKU\S-1-5-21-841361005-909514878-2309378359-1002\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - No Path
CHR HKLM-x32\...\Chrome\Extension: [mjdepfkicdcciagbigfcmdhknnoaaegf] - C:\Program Files (x86)\Linguarde\wcxChrome.crx [Not Found]

S3 dcdbas; system32\DRIVERS\dcdbas64.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S2 X5XSEx_Pr143; \??\C:\Program Files (x86)\Free Ride Games\X5XSEx_Pr143.Sys [X]

2015-01-06 01:38 - 2015-01-06 01:38 - 00000000 ____D () C:\Users\Ruda\AppData\Local\Avg
2015-01-06 01:37 - 2015-01-08 17:47 - 00000000 ____D () C:\ProgramData\AVG
2015-01-09 23:52 - 2013-11-03 13:54 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 23:51 - 2014-10-20 19:27 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-09 23:38 - 2014-10-20 19:27 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-09 21:55 - 2014-09-30 19:27 - 00000924 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job
2015-01-09 19:57 - 2014-10-19 14:45 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-09 00:55 - 2014-09-30 19:27 - 00000902 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job
2015-01-07 01:15 - 2014-12-05 01:15 - 00000280 _____ () C:\Windows\Tasks\_UPDATES.job
2015-01-09 15:01 - 2014-12-05 01:15 - 00000272 _____ () C:\Windows\Tasks\_DEFAULT.job
2015-01-04 23:43 - 2014-09-12 22:45 - 00000452 _____ () C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeAAMUpdater-1.0 => value deleted successfully.
HKU\S-1-5-21-841361005-909514878-2309378359-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Synchronizer => value deleted successfully.
HKU\S-1-5-21-841361005-909514878-2309378359-1002\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update => value deleted successfully.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => Key deleted successfully.
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => Key not found.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
"HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\TopResultURLFallback http://search.certified-toolbar.com?si= ... => Value not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7ffa5f54-1c4f-46de-8576-c271a0dd482f}" => Key deleted successfully.
"HKCR\CLSID\{7ffa5f54-1c4f-46de-8576-c271a0dd482f}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7ffa5f54-1c4f-46de-8576-c271a0dd482f}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{7ffa5f54-1c4f-46de-8576-c271a0dd482f}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{AEAF002F-E6D8-4A21-ABD3-2B309B79A6CE}" => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{7ffa5f54-1c4f-46de-8576-c271a0dd482f} => value deleted successfully.
HKCR\CLSID\{7ffa5f54-1c4f-46de-8576-c271a0dd482f} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => value deleted successfully.
HKCR\Wow6432Node\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7ffa5f54-1c4f-46de-8576-c271a0dd482f} => value deleted successfully.
HKCR\Wow6432Node\CLSID\{7ffa5f54-1c4f-46de-8576-c271a0dd482f} => Key not found.
HKU\S-1-5-21-841361005-909514878-2309378359-1002\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => value deleted successfully.
HKCR\CLSID\{25E2E5C9-C43C-4EE8-B23E-4383915F2BCE} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5} => Key not found.
"HKCR\PROTOCOLS\Handler\WSISVCUchrome" => Key deleted successfully.
"HKLM\SOFTWARE\Google\Chrome\Extensions\hdokiejnpimakedhajhdlcegeplioahd" => Key deleted successfully.
"HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Google\Chrome\Extensions\apdfllckaahabafndbhieahigkjlhalf" => Key deleted successfully.
"HKU\S-1-5-21-841361005-909514878-2309378359-1002\SOFTWARE\Google\Chrome\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hdokiejnpimakedhajhdlcegeplioahd" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mjdepfkicdcciagbigfcmdhknnoaaegf" => Key deleted successfully.
dcdbas => Service deleted successfully.
esgiguard => Service deleted successfully.
MBAMSwissArmy => Service deleted successfully.
X5XSEx_Pr143 => Service deleted successfully.
C:\Users\Ruda\AppData\Local\Avg => Moved successfully.
C:\ProgramData\AVG => Moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job => Moved successfully.
C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002Core.job => Moved successfully.
C:\Windows\Tasks\_UPDATES.job => Moved successfully.
C:\Windows\Tasks\_DEFAULT.job => Moved successfully.
C:\Windows\Tasks\Wise Disk Cleaner Schedule Task.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.3 GB temporary data.


The system needed a reboot.

==== End of Fixlog 10:19:19 ====

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#4 Příspěvek od Márty84 »

:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.


:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#5 Příspěvek od rudy630 »

# AdwCleaner v4.107 - Report created 10/01/2015 at 12:27:34
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Ruda - RUDA-PC
# Running from : C:\Users\Ruda\Downloads\adwcleaner_4.107.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plus500
Folder Deleted : C:\Program Files (x86)\Plus500
Folder Deleted : C:\Users\Ruda\AppData\Local\Plus500
Folder Deleted : C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plus500

***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.17496


-\\ Mozilla Firefox v34.0 (x86 cs)


-\\ Google Chrome v39.0.2171.95

[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com/?si=71578&st=bs&tid=8195&ver=4.9&ts=1383433200000.000007&tguid=71578-8195-1383444228385-7077C284AEBE65440D00D038ED049FA9&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com/?si=71578&st=bs&tid=8195&ver=4.9&ts=1383433200000.000007&tguid=71578-8195-1383444228385-7077C284AEBE65440D00D038ED049FA9&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://go.speedbit.com/search.aspx?s=E2Ob&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3 ... rms}&SSPV=
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3 ... rms}&SSPV=
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://start.funmoods.com/results.php?f=4&a=ddrnw&q={searchTerms}

-\\ Comodo Dragon v36.1.1.21

[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com/?si=71578&st=bs&tid=8195&ver=4.9&ts=1383433200000.000007&tguid=71578-8195-1383444228385-7077C284AEBE65440D00D038ED049FA9&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://search.certified-toolbar.com/?si=71578&st=bs&tid=8195&ver=4.9&ts=1383433200000.000007&tguid=71578-8195-1383444228385-7077C284AEBE65440D00D038ED049FA9&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://go.speedbit.com/search.aspx?s=E2Ob&q={searchTerms}
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3 ... rms}&SSPV=
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3 ... rms}&SSPV=
[C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Deleted [Search Provider] : hxxp://start.funmoods.com/results.php?f=4&a=ddrnw&q={searchTerms}

*************************

AdwCleaner[R25].txt - [5136 octets] - [01/12/2014 21:27:46]
AdwCleaner[R27].txt - [3963 octets] - [27/12/2014 00:33:02]
AdwCleaner[R28].txt - [3294 octets] - [09/01/2015 23:32:39]
AdwCleaner[R29].txt - [2949 octets] - [10/01/2015 12:25:38]
AdwCleaner[S25].txt - [6797 octets] - [01/12/2014 21:29:44]
AdwCleaner[S27].txt - [5521 octets] - [27/12/2014 00:35:40]
AdwCleaner[S28].txt - [4886 octets] - [09/01/2015 23:34:50]
AdwCleaner[S29].txt - [4389 octets] - [10/01/2015 12:27:34]



Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 10.1.2015
Čas skenování: 12:41:31
Protokol: log.MBM.txt
Správce: Ano

Verze: 2.00.4.1028
Databáze malwaru: v2015.01.10.10
Databáze rootkitů: v2015.01.07.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Ruda

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 477698
Uplynulý čas: 38 min, 10 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Žádné zákerné zjištěny položek)

Moduly: 0
(Žádné zákerné zjištěny položek)

Klíče registru: 3
PUP.Optional.InboxToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, , [06bc3cb96c1d49ed0c95b72ed62c4fb1],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, , [51716b8aed9cd6605b722bbce91b13ed],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, , [8042a352cebb39fd5379945316ee57a9],

Hodnoty registru: 1
PUP.Optional.FreeMakeConverter.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fmconverter@gmail.com, C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\, , [556d9e572168350187133240dc27e917]

Data registru: 0
(Žádné zákerné zjištěny položek)

Složky: 5
Rogue.Multiple, C:\Users\Ruda\AppData\Local\QIP, , [a220cf265b2e23134b78002e63a0b34d],
PUP.Optional.MindSpark.A, C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\INTERNETSPEEDTRACKER_9T, , [467cf005cebb84b28a24e25915eea858],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.IHlpr.A, C:\Users\Ruda\AppData\Roaming\IHlpr\26B6CBC0C3E840E0BE837766011035DB, , [695945b05534d95db3fb283cf211aa56],

Soubory: 21
PUP.Optional.OpenCandy, C:\Users\Ruda\AppData\Roaming\uTorrent\updates\3.4.0_30596.exe, , [05bd6c89b6d356e0f846be3d857fb24e],
PUP.Optional.Opencandy, C:\Users\Ruda\AppData\Roaming\rmi\offer_downloader.exe, , [caf88e6769200e28517837973fc349b7],
PUP.Optional.Softonic, C:\Users\Ruda\Downloads\SoftonicDownloader_for_ashampoo-hdd-control.exe, , [14aed421f792c274793958020bf5956b],
PUP.Optional.Softonic.A, C:\Users\Ruda\Downloads\SoftonicDownloader_for_cheat-engine.exe, , [6260c035abded06665f6370a9b667c84],
PUP.Optional.DownloadAdmin, C:\Users\Ruda\Downloads\installer_java_English.exe, , [0cb6777ea7e280b6a5ec1c3ca25e4ab6],
PUP.Optional.OpenCandy, C:\Users\Ruda\Downloads\PhotoScape_V3.7.exe, , [cdf5d025375278becb8bc9ec37ceb54b],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, , [42800beab9d090a6a02c9f6cc43e9868],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_plnkhmnoajbfccclonaeepohggeolcih_0.localstorage, , [19a94baa7c0d0630fe47364256ad4db3],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, , [f1d119dca2e786b022aef6f1c0448977],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\000003.log, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\CURRENT, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOCK, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\LOG, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.Conduit.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojpijjmpahflnipadmlpgbjmagmjchkk\MANIFEST-000002, , [9a286d888bfe4bebbe9ea7b1ce356a96],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\000115.ldb, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\000117.ldb, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\000124.log, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\CURRENT, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\LOCK, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\LOG, , [764c9461a1e8033364e97be03ac913ed],
PUP.Optional.CrossRider.A, C:\Users\Ruda\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\plnkhmnoajbfccclonaeepohggeolcih\MANIFEST-000122, , [764c9461a1e8033364e97be03ac913ed],

Fyzické sektory: 0
(Žádné zákerné zjištěny položek)


(end)

########## EOF - C:\AdwCleaner\AdwCleaner[S29].txt - [4450 octets] ##########

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#6 Příspěvek od Márty84 »

Vsechny nalezy MBAM hodte do karanteny. Po restartu pc udelejte novy test - tentokrat opravdu podle navodu, cili vlastni sken vsech disku, aby byl proskenovan cely pocitac. Napiste vysledek testu a podle nej zvolim dalsi postup.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#7 Příspěvek od rudy630 »

Omlouvám se za zpoždění, ale tady jsme byli kvůli větříku bez elektřiny.

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 10.1.2015
Čas skenování: 20:35:41
Protokol: log.MBM.txt
Správce: Ano

Verze: 2.00.4.1028
Databáze malwaru: v2015.01.10.15
Databáze rootkitů: v2015.01.07.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto

OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: Ruda

Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 704845
Uplynulý čas: 3 hod, 56 min, 40 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Žádné zákerné zjištěny položek)

Moduly: 0
(Žádné zákerné zjištěny položek)

Klíče registru: 0
(Žádné zákerné zjištěny položek)

Hodnoty registru: 0
(Žádné zákerné zjištěny položek)

Data registru: 0
(Žádné zákerné zjištěny položek)

Složky: 0
(Žádné zákerné zjištěny položek)

Soubory: 5
PUP.Riskware.Patcher, C:\ProgramData\Comodo\Cis\Quarantine\data\{2A53F686-CDE6-4190-9880-EB45E4E84057}, , [cff825d0b5d4b383b9d06ebf50b10000],
PUP.Optional.Linkey.A, C:\ProgramData\Comodo\Cis\Quarantine\data\{B94C615B-C33F-4D44-950C-F98CDC2766CA}, , [e5e2ce271079132376f4ffa949b88779],
PUP.Riskware.Patcher, C:\ProgramData\Comodo\Cis\Quarantine\data\{E1E7FDAF-F99F-46A8-AE55-B69505B8E5CF}, , [4e79f1040d7c310507820627fb06a65a],
PUP.Optional.OpenCandy, C:\VTRoot\HarddiskVolume3\Users\Ruda\AppData\Local\Temp\is-GFJU3.tmp\OCSetupHlp.dll, , [c403c92c1b6e999da833d4e181848a76],
PUP.Optional.OpenCandy, C:\VTRoot\HarddiskVolume3\Users\Ruda\AppData\Local\Temp\is-H7LKE.tmp\OCSetupHlp.dll, , [2a9d5a9bf693bc7ab823b203d233d42c],

Fyzické sektory: 0
(Žádné zákerné zjištěny položek)


(end)

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#8 Příspěvek od Márty84 »

:arrow: Nalezy hodte do karanteny, pak MBAM odinstalujte.

:arrow: Dejte log z RSITx64 http://images.malwareremoval.com/random/RSITx64.exe , navod zde http://forum.viry.cz/viewtopic.php?f=13&t=130786
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#9 Příspěvek od rudy630 »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Ruda at 2015-01-11 01:01:32
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 72 GB (38%) free of 191 GB
Total RAM: 3980 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:01:50, on 11.1.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
C:\Windows\SysWOW64\ACEngSvr.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
C:\Users\Ruda\AppData\Local\Facebook\Update\FacebookUpdate.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\trend micro\Ruda.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: IESpeakDoc - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: LastPass Vault - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: DownloadHelper Class - {FF2573AE-E1ED-40e1-83BA-F544CB2EE135} - C:\Program Files (x86)\Common Files\Download Helper\DownloadHelper.dll
O2 - BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll
O3 - Toolbar: LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
O4 - HKLM\..\Run: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
O4 - HKLM\..\Run: [DelaypluginInstall] C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe
O4 - Startup: SystemExplorerDisabled
O4 - Global Startup: Install LastPass FF RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe
O4 - Global Startup: Install LastPass IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: LastPass - file://C:\Users\Ruda\AppData\LocalLow\LastPass\context.html?cmd=lastpass
O8 - Extra context menu item: LastPass Vyplňování formulářů - file://C:\Users\Ruda\AppData\LocalLow\LastPass\context.html?cmd=fillforms
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra 'Tools' menuitem: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll
O9 - Extra button: (no name) - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra 'Tools' menuitem: Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - http://www.asus.com/support/asusTek_sys_ctrl3.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{E557249B-EC4D-4E00-9A90-D94FCB0F2C10}: NameServer = 156.154.70.25,156.154.71.25
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: c:\windows\syswow64\nvinit.dll c:\windows\syswow64\nvinit.dll c:\windows\syswow64\nvinit.dll, c:\windows\syswow64\nvinit.dll, C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe
O23 - Service: AtherosSvc - Atheros Commnucations - C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @%systemroot%\system32\CISVC.EXE,-1 (CISVC) - Unknown owner - C:\Windows\system32\CISVC.EXE (file missing)
O23 - Service: COMODO LPS Launcher (CLPSLauncher) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: COMODO Programs Manager Service (CPMService) - Unknown owner - C:\Program Files\COMODO\COMODO Programs Manager\CPMService.exe
O23 - Service: COMODO Dragon Update Service (DragonUpdater) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GeekBuddyRSP Server (GeekBuddyRSP) - Comodo Security Solutions, Inc. - C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Internet Explorer ETW Collector Service (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\Windows\system32\mqsvc.exe (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: Zachytávání pro službu SNMP (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: System Explorer Service (SystemExplorerHelpService) - Mister Group - C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: VideoAcceleratorService - SPEEDbit - C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAtheros Bt&Wlan Coex Agent - Atheros - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe

--
End of file - 15457 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe"
"C:\Windows\system32\nvvsvc.exe"
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\Windows\system32\nvvsvc.exe -session -first
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
C:\Windows\System32\spoolsv.exe
taskeng.exe {2FF9008E-F185-4888-8737-D50BFA8DC48E}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\system32\svchost.exe -k apphost
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe"
"C:\Program Files (x86)\Bluetooth Suite\adminservice.exe"
C:\Windows\system32\CISVC.EXE
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Program Files\COMODO\COMODO Programs Manager\CPMService.exe"
"C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe"
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -service
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe"
C:\Windows\system32\mqsvc.exe
"C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe" --defaults-file="C:\Program Files\MySQL\MySQL Server 5.6\my.ini" MySQL
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Windows\SysWOW64\ssins.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
C:\Windows\System32\vds.exe
C:\Windows\system32\viakaraokesrv.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss 287fe442-4e05-4d43-868e-fa50f304ed96 1
C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe -start -scm
\??\C:\Windows\system32\conhost.exe "1572301232-898886342-1758032951-214160193710891136622075448850-17506874191178935540
C:\Windows\system32\svchost.exe -k iissvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
"C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s
WLIDSvcM.exe 3920
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
"taskhost.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
"C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
ATKOSD.exe
KBFiltr.exe
WDC.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
taskeng.exe {456F9064-B8D8-4ECD-A1EE-3A11D06CCA88}
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
\??\C:\Windows\system32\conhost.exe "9264690891999550831-369289816-12495799112002679510-1752137165759985912-1303605048
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
taskeng.exe {F94CEDE3-5F80-42D8-9E92-71DE6E758BE0}
"C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x64\QuickGesture64.exe"
"C:\Program Files (x86)\ASUS\ASUS Virtual Touch\QuickGesture\x86\QuickGesture.exe"
"C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
C:\Windows\System32\alg.exe
C:\Windows\servicing\TrustedInstaller.exe
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
"C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\Windows\SysWOW64\ACEngSvr.exe -Embedding
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDGesture.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe"
"C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
"C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe" -controlservice -slave
"C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
C:\Users\Ruda\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\PerfLogs\Desktop\RSITx64.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 840 844 852 65536 848

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job - C:\Users\Ruda\AppData\Local\Google\Update\GoogleUpdate.exe# /ua /installsource scheduler#

=========Mozilla firefox=========

ProfilePath - C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244

prefs.js - "browser.startup.homepage" - "https://www.seznam.cz/?logged=1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0]
"Description"=Exent® AOD Gecko Plugin
"Path"=C:\Program Files (x86)\Free Ride Games\npExentCtl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@google.com/npPicasa3,version=3.0.0]
"Description"=Picasa3 plugin
"Path"=C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=10.67.2]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@oberon-media.com/ONCAdapter]
"Description"=Oberon com adapter plugin
"Path"=C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Skype Technologies S.A..com/Skype Web Plugin]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.0.8]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.0]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.2]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\www.exent.com/GameTreatWidget]
"Description"=
"Path"=C:\Program Files (x86)\Free Ride Games\NPGameTreatPlugin.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 16.0.0.235 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@lastpass.com/NPLastPass]
"Description"=
"Path"=C:\Program Files (x86)\LastPass\nplastpass.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Skype Technologies S.A..com/Skype Web Plugin]
"Description"=Skype Web Plugin
"Path"=C:\Program Files (x86)\SkypeWebPlugin\npSkypeWebPlugin64.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.0.7]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}

C:\Program Files (x86)\Mozilla Firefox\plugins\
nppdf32.dll
npPDFXCviewNPPlugin.dll

C:\Users\Ruda\AppData\Roaming\Mozilla\Firefox\Profiles\g3adrwsv.default-1413532086244\extensions\
support@lastpass.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-11-04 218784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 529664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2014-11-12 886480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-11-12 2334928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF2573AE-E1ED-40e1-83BA-F544CB2EE135}]
DownloadHelper Class - C:\Program Files\Common Files\Download Helper\DownloadHelperx64.dll [2011-01-07 905216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-08-12 715016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-06 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-05-31 52352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95D9ECF5-2A4D-4550-BE49-70D42F71296E}]
LastPass Vault - C:\Program Files (x86)\LastPass\LPToolbar.dll [2014-11-27 608768]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2014-11-12 710864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-06 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FF2573AE-E1ED-40e1-83BA-F544CB2EE135}]
DownloadHelper Class - C:\Program Files (x86)\Common Files\Download Helper\DownloadHelper.dll [2011-01-07 626688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664}]
Adblock Plus for IE Browser Helper Object - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-08-12 606472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - LastPass Toolbar - C:\Program Files (x86)\LastPass\LPToolbar.dll [2014-11-27 608768]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-02-19 2661672]
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2011-05-26 361984]
"AtherosBtStack"=C:\Program Files (x86)\Bluetooth Suite\btvstack.exe [2012-05-31 1023616]
"AthBtTray"=C:\Program Files (x86)\Bluetooth Suite\athbttray.exe [2012-05-31 801920]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-12-13 2824504]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-12-13 2531472]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2014-01-29 171992]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2014-01-29 399832]
"Persistence"=C:\Windows\system32\igfxpers.exe [2014-01-29 442328]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2014-12-09 1297112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSWebStorage]
C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.144.298\AsusWSPanel.exe [2012-11-05 740736]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Family Tree Builder Update]
C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe [2013-11-12 2532864]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoobzoYouTubeAccelerator]
C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe /startup []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google+ Auto Backup]
C:\Users\Ruda\AppData\Local\Programs\Google\Google+ Auto Backup\Google+ Auto Backup.exe [2014-08-12 3746120]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup]
C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
C:\Users\Ruda\AppData\Roaming\ICQM\icq.exe -CU []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magic Screenshot.exe]
C:\Program Files (x86)\RoverSoft\Magic Screenshot\Magic Screenshot.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
C:\Program Files (x86)\Mobogenie\DaemonProcess.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Skype.lnk]
C:\PROGRA~2\Skype\Phone\Skype.exe [2014-12-11 30872168]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Ruda^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Odeslat do OneNote.lnk]
C:\PROGRA~1\MICROS~4\root\office15\ONENOTEM.EXE [2014-09-23 195240]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2000-01-01 292088]
"ACMON"=C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-02-21 102568]
"Wireless Console 3"=C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2012-02-03 2321072]
"ATKOSD2"=C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2012-06-25 322208]
"ATKMEDIA"=C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [2012-06-19 174752]
"HControlUser"=C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [2009-06-19 105016]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2014-12-13 3838800]
"tvncontrol"=C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2014-12-25 2327248]
"iSkysoft Helper Compact.exe"=C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2015-01-07 2066432]
"DelaypluginInstall"=C:\ProgramData\iSkysoft\Video Converter Ultimate\DelayPluginI.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Install LastPass FF RunOnce.lnk - C:\Program Files (x86)\Common Files\lpuninstall.exe
Install LastPass IE RunOnce.lnk - C:\Program Files (x86)\Common Files\lpuninstall.exe

C:\Users\Ruda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
SystemExplorerDisabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\System32\nvinitx.dll, C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2014-01-29 442880]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"undockwithoutlogon"=1
"ShutdownWithoutLogon"=1
"NoDispCPL"=0
"NoDispSettingsPage"=0
"NoDispScrSavPage"=0
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoViewContextMenu"=0
"NoFileAssociate"=0
"NoRun"=0
"NoClose"=0
"StartMenuLogoff"=0
"NoResolveTrack"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3codecp"=l3codecp.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.txt - open -

======List of files/folders created in the last 1 month======

2015-01-11 01:01:32 ----D---- C:\rsit
2015-01-10 12:38:37 ----D---- C:\ProgramData\Malwarebytes
2015-01-10 00:51:00 ----D---- C:\Program Files\7-Zip
2015-01-09 23:20:39 ----D---- C:\FRST
2015-01-09 18:43:39 ----D---- C:\Users\Ruda\AppData\Roaming\VitySoft
2015-01-09 11:39:44 ----D---- C:\Users\Ruda\AppData\Roaming\WinRAR
2015-01-09 11:09:13 ----D---- C:\Program Files\CPUID
2015-01-08 18:11:12 ----A---- C:\Windows\system32\cpmnat.exe
2015-01-08 17:58:29 ----A---- C:\Windows\system32\drivers\cumon.sys
2015-01-08 17:58:26 ----A---- C:\Windows\system32\drivers\evdd.sys
2015-01-07 20:00:39 ----D---- C:\Users\Ruda\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
2015-01-07 19:59:16 ----D---- C:\ProgramData\iSkysoft Video Converter Ultimate
2015-01-07 19:59:10 ----D---- C:\ProgramData\iSkysoft
2015-01-06 15:05:49 ----A---- C:\Windows\system32\drivers\anvsnddrv.sys
2015-01-06 01:12:56 ----D---- C:\Program Files (x86)\Anvsoft
2015-01-03 20:35:24 ----D---- C:\Program Files (x86)\TeamViewer
2015-01-02 01:10:57 ----A---- C:\Windows\CUAppUsage.Dat
2015-01-01 22:37:15 ----AH---- C:\fileimage.dat
2014-12-31 12:24:11 ----A---- C:\Windows\SYSWOW64\DfSdkBt32.exe
2014-12-31 12:24:11 ----A---- C:\Windows\system32\DfSdkBt.exe
2014-12-30 02:32:32 ----D---- C:\Users\Ruda\AppData\Roaming\Canneverbe Limited
2014-12-30 02:32:28 ----D---- C:\Program Files (x86)\CDBurnerXP
2014-12-30 02:25:10 ----D---- C:\Program Files (x86)\Q-Dir
2014-12-28 20:04:08 ----A---- C:\Users\Ruda\AppData\Roaming\Network Meter_Usage.ini
2014-12-28 03:28:09 ----A---- C:\Windows\system32\drivers\fvstore.dat
2014-12-27 20:56:21 ----D---- C:\Users\Ruda\AppData\Roaming\IHlpr
2014-12-27 00:58:22 ----D---- C:\Free Rapid
2014-12-26 23:41:02 ----D---- C:\ProgramData\PCB_Win7_
2014-12-25 14:40:05 ----A---- C:\Windows\system32\drivers\sfi.dat
2014-12-25 14:36:18 ----D---- C:\Program Files\COMODO
2014-12-25 14:35:48 ----A---- C:\Windows\SYSWOW64\certsentry.dll
2014-12-25 14:35:48 ----A---- C:\Windows\system32\certsentry.dll
2014-12-25 14:35:37 ----D---- C:\Program Files (x86)\Comodo
2014-12-25 14:35:33 ----D---- C:\ProgramData\Comodo Downloader
2014-12-25 14:33:09 ----D---- C:\ProgramData\Comodo
2014-12-24 21:47:49 ----D---- C:\Users\Ruda\AppData\Roaming\MediaInfo
2014-12-24 15:21:18 ----D---- C:\Program Files (x86)\Microsoft ASP.NET
2014-12-24 12:34:20 ----D---- C:\Windows\SYSWOW64\NV
2014-12-24 12:34:20 ----D---- C:\Windows\system32\NV
2014-12-24 12:29:26 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2014-12-24 12:29:26 ----A---- C:\Windows\system32\nvwgf2umx.dll
2014-12-24 12:29:26 ----A---- C:\Windows\system32\nvumdshimx.dll
2014-12-24 12:29:25 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2014-12-24 12:29:25 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2014-12-24 12:29:25 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2014-12-24 12:29:25 ----A---- C:\Windows\system32\nvopencl.dll
2014-12-24 12:29:25 ----A---- C:\Windows\system32\nvoglv64.dll
2014-12-24 12:29:25 ----A---- C:\Windows\system32\nvoglshim64.dll
2014-12-24 12:29:25 ----A---- C:\Windows\system32\drivers\nvpciflt.sys
2014-12-24 12:29:24 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2014-12-24 12:29:24 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2014-12-24 12:29:24 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\nvinitx.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\NvIFR64.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\NvFBC64.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\nvdispgenco6434709.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\nvdispco6434709.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\nvd3dumx.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\nvcuvid.dll
2014-12-24 12:29:24 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2014-12-24 12:29:23 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2014-12-24 12:29:23 ----A---- C:\Windows\system32\nvcuda.dll
2014-12-24 12:29:22 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2014-12-24 12:29:22 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2014-12-24 12:29:22 ----A---- C:\Windows\system32\nvcompiler.dll
2014-12-24 11:55:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-12-24 11:55:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-12-24 02:15:52 ----D---- C:\Users\Ruda\AppData\Roaming\Oberon Games
2014-12-24 02:11:36 ----D---- C:\ProgramData\Oberon Games
2014-12-23 13:26:17 ----D---- C:\Users\Ruda\AppData\Roaming\LSoft
2014-12-23 13:26:07 ----D---- C:\Program Files (x86)\LSoft
2014-12-23 11:57:59 ----D---- C:\Users\Ruda\AppData\Roaming\Q-Dir
2014-12-22 02:44:14 ----D---- C:\Program Files\Q-Dir
2014-12-17 22:54:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-12-17 22:54:38 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-17 12:49:34 ----D---- C:\Program Files (x86)\Freemake
2014-12-16 22:29:23 ----D---- C:\ProgramData\FileOpen
2014-12-16 22:29:22 ----D---- C:\Users\Ruda\AppData\Roaming\FileOpen
2014-12-16 22:26:25 ----D---- C:\Users\Ruda\AppData\Roaming\Downloaded Installations
2014-12-16 17:05:16 ----D---- C:\Program Files (x86)\Flock
2014-12-15 16:28:21 ----D---- C:\Program Files (x86)\PicPick
2014-12-13 12:10:59 ----D---- C:\ProgramData\SendMails

======List of files/folders modified in the last 1 month======

2015-01-11 01:01:35 ----D---- C:\Program Files\trend micro
2015-01-11 00:56:09 ----D---- C:\Windows\system32\drivers
2015-01-11 00:56:09 ----D---- C:\Program Files (x86)
2015-01-11 00:54:31 ----SHD---- C:\System Volume Information
2015-01-11 00:54:25 ----D---- C:\Windows
2015-01-11 00:50:46 ----D---- C:\Windows\temp
2015-01-11 00:50:33 ----D---- C:\Windows\system32\config
2015-01-11 00:49:08 ----D---- C:\Windows\Microsoft.NET
2015-01-10 20:32:16 ----D---- C:\Windows\Prefetch
2015-01-10 14:03:03 ----D---- C:\Windows\Migration
2015-01-10 14:02:58 ----D---- C:\Users\Ruda\AppData\Roaming\rmi
2015-01-10 12:54:10 ----DC---- C:\AdwCleaner
2015-01-10 12:38:37 ----D---- C:\ProgramData
2015-01-10 12:08:29 ----D---- C:\Users
2015-01-10 10:17:59 ----D---- C:\Windows\system32\drivers\etc
2015-01-10 10:17:58 ----D---- C:\Windows\Tasks
2015-01-10 10:10:11 ----D---- C:\Users\Ruda\AppData\Roaming\uTorrent
2015-01-10 00:51:03 ----SHDC---- C:\Config.Msi
2015-01-10 00:51:03 ----SHD---- C:\Windows\Installer
2015-01-10 00:51:00 ----RD---- C:\Program Files
2015-01-09 21:53:53 ----D---- C:\Users\Ruda\AppData\Roaming\Ashampoo Photo Commander 11
2015-01-09 21:53:15 ----D---- C:\Users\Ruda\AppData\Roaming\Ashampoo
2015-01-09 18:47:00 ----D---- C:\Users\Ruda\AppData\Roaming\vlc
2015-01-09 18:00:21 ----D---- C:\Windows\system32\wbem
2015-01-09 17:59:28 ----D---- C:\Windows\system32\catroot2
2015-01-09 17:59:26 ----D---- C:\Windows\registration
2015-01-09 17:42:18 ----D---- C:\Users\Ruda\AppData\Roaming\Skype
2015-01-08 23:00:18 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-01-08 21:32:39 ----D---- C:\Program Files (x86)\Internet Explorer
2015-01-08 21:31:56 ----D---- C:\Windows\SysWOW64
2015-01-08 21:18:48 ----D---- C:\Windows\inf
2015-01-08 19:23:23 ----D---- C:\Users\Ruda\AppData\Roaming\QuickScan
2015-01-08 18:58:59 ----D---- C:\ProgramData\Ashampoo
2015-01-08 18:54:18 ----D---- C:\Program Files (x86)\Ashampoo
2015-01-08 18:11:12 ----D---- C:\Windows\System32
2015-01-08 17:37:10 ----D---- C:\Users\Ruda\AppData\Roaming\FastStone
2015-01-08 17:33:33 ----D---- C:\Users\Ruda\AppData\Roaming\AnvSoft
2015-01-08 15:01:28 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-01-07 19:59:58 ----D---- C:\Program Files (x86)\Common Files
2015-01-07 02:39:29 ----D---- C:\Windows\debug
2015-01-07 01:49:25 ----D---- C:\Program Files\Recuva
2015-01-06 15:07:08 ----D---- C:\Windows\system32\DriverStore
2015-01-05 00:21:08 ----D---- C:\Users\Ruda\AppData\Roaming\TeamViewer
2015-01-04 21:08:35 ----D---- C:\Windows\SYSWOW64\drivers
2015-01-04 02:32:22 ----D---- C:\Program Files (x86)\Google
2015-01-03 20:35:56 ----D---- C:\Windows\system32\Tasks
2015-01-03 20:35:40 ----RSD---- C:\Windows\Fonts
2015-01-03 12:05:12 ----D---- C:\Program Files (x86)\Recepty doma
2015-01-02 02:46:15 ----D---- C:\Program Files\CCleaner
2015-01-02 01:11:38 ----D---- C:\Windows\system32\wfp
2015-01-02 01:09:52 ----D---- C:\Program Files (x86)\Cheat Engine 6.3
2015-01-02 01:08:44 ----HDC---- C:\VTRoot
2015-01-01 14:05:53 ----A---- C:\Users\Ruda\AppData\Roaming\inst.exe
2014-12-30 11:24:02 ----A---- C:\Windows\SYSWOW64\mediarcpt.dll
2014-12-30 02:26:23 ----A---- C:\Windows\Q-Dir.ini
2014-12-28 21:14:22 ----D---- C:\Program Files\Tracker Software
2014-12-28 20:45:22 ----AD---- C:\ProgramData\Temp
2014-12-26 17:59:03 ----A---- C:\Users\Ruda\AppData\Roaming\All CPU MeterV3_Settings.ini
2014-12-26 01:48:01 ----N---- C:\Windows\system32\MpSigStub.exe
2014-12-25 14:36:30 ----D---- C:\Windows\winsxs
2014-12-24 15:21:22 ----RSD---- C:\Windows\assembly
2014-12-24 12:34:28 ----DC---- C:\Temp
2014-12-24 12:34:18 ----D---- C:\ProgramData\NVIDIA
2014-12-24 05:08:19 ----SDC---- C:\Downloads
2014-12-24 03:50:48 ----D---- C:\ProgramData\Atheros
2014-12-24 03:50:00 ----SHDC---- C:\$RECYCLE.BIN
2014-12-23 22:01:47 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2014-12-23 22:01:47 ----A---- C:\Windows\SYSWOW64\OpenAL32.dll
2014-12-23 22:01:47 ----A---- C:\Windows\system32\wrap_oal.dll
2014-12-23 22:01:47 ----A---- C:\Windows\system32\OpenAL32.dll
2014-12-23 11:37:28 ----D---- C:\Users\Ruda\AppData\Roaming\PhotoScape
2014-12-23 11:30:08 ----D---- C:\ProgramData\Package Cache
2014-12-23 10:24:00 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2014-12-23 10:21:59 ----D---- C:\Program Files\Microsoft Office 15
2014-12-22 17:49:51 ----D---- C:\Program Files (x86)\System Explorer
2014-12-22 03:19:08 ----D---- C:\Program Files\Common Files
2014-12-22 03:06:29 ----D---- C:\Program Files (x86)\LibreOffice 4
2014-12-20 00:35:08 ----D---- C:\ProgramData\Skype
2014-12-20 00:35:05 ----RD---- C:\Program Files (x86)\Skype
2014-12-17 14:29:45 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2014-12-17 12:51:48 ----D---- C:\ProgramData\Freemake
2014-12-15 16:28:44 ----D---- C:\Users\Ruda\AppData\Roaming\PicPick
2014-12-13 11:08:08 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2014-12-13 11:08:08 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2014-12-13 11:08:08 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2014-12-13 11:08:08 ----A---- C:\Windows\system32\nvapi64.dll
2014-12-13 09:03:15 ----A---- C:\Windows\system32\nvsvc64.dll
2014-12-13 09:03:15 ----A---- C:\Windows\system32\nvcpl.dll
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nvvsvc.exe
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nvsvcr.dll
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nvshext.dll
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nvmctray.dll
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nv3dappshextr.dll
2014-12-13 09:03:13 ----A---- C:\Windows\system32\nv3dappshext.dll
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-12-13 01:12:24 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspcap64.dll
2014-12-13 01:12:12 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-12-12 14:00:21 ----D---- C:\Windows\rescache
2014-12-12 01:39:16 ----D---- C:\Program Files\MediaCoder

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 cumon;cumon; C:\Windows\system32\drivers\cumon.sys [2011-09-05 205512]
R0 Evdd;evdd; C:\Windows\system32\drivers\evdd.sys [2011-09-05 19568]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-12-23 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2000-01-01 20464]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2014-12-13 31376]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2011-09-07 17536]
R1 CFRMD;CFRMD; C:\Windows\system32\DRIVERS\CFRMD.sys [2014-06-26 37976]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys [2014-12-09 20184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys [2014-12-09 792648]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys [2014-12-09 45880]
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys [2014-12-09 104608]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R3 AiCharger;ASUS Charger Driver; C:\Windows\system32\DRIVERS\AiCharger.sys [2012-02-29 17152]
R3 anvsnddrv;AnvSoft Virtual Sound Device; C:\Windows\system32\drivers\anvsnddrv.sys [2015-01-06 33872]
R3 AsusVBus;AsusVBus; C:\Windows\system32\DRIVERS\AsusVBus.sys [2012-04-12 35968]
R3 AsusVTouch;AsusVTouch; C:\Windows\system32\DRIVERS\AsusVTouch.sys [2012-04-12 16512]
R3 AthBTPort;Atheros Virtual Bluetooth Class; C:\Windows\system32\DRIVERS\btath_flt.sys [2012-05-31 36480]
R3 athr;Qualcomm Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys [2014-04-06 3979776]
R3 BTATH_A2DP;Bluetooth A2DP Audio Driver; C:\Windows\system32\drivers\btath_a2dp.sys [2012-05-31 341120]
R3 btath_avdt;Atheros Bluetooth AVDT Service; C:\Windows\system32\drivers\btath_avdt.sys [2012-05-31 111232]
R3 BTATH_BUS;Atheros Bluetooth Bus; C:\Windows\system32\DRIVERS\btath_bus.sys [2012-05-31 30848]
R3 BTATH_HCRP;Bluetooth HCRP Server driver; C:\Windows\system32\DRIVERS\btath_hcrp.sys [2012-05-31 168064]
R3 BTATH_LWFLT;Bluetooth LWFLT Device; C:\Windows\system32\DRIVERS\btath_lwflt.sys [2012-05-31 68736]
R3 BTATH_RCP;Bluetooth AVRCP Device; C:\Windows\system32\DRIVERS\btath_rcp.sys [2012-05-31 281472]
R3 BtFilter;BtFilter; C:\Windows\system32\DRIVERS\btfilter.sys [2014-03-18 589000]
R3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2012-02-24 80384]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2012-02-19 200488]
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2009-03-18 33856]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-01-29 5363200]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2000-01-01 342528]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2000-01-01 358896]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2000-01-01 795632]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2009-07-20 15416]
R3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C62x64.sys [2000-01-01 117912]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys []
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2000-01-01 100312]
R3 MQAC;@mqutil.dll,-6101; C:\Windows\system32\drivers\mqac.sys [2009-07-14 189440]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-12-13 19600]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-11-22 38032]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service; C:\Windows\system32\drivers\viahduaa.sys [2000-01-01 689840]
S1 KDHacker;KDHacker; \??\c:\program files (x86)\kingsoft\kingsoft antivirus\security\kxescan\kdhacker64.sys []
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [2009-06-10 1146880]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 CLVirtualBus01;CyberLink Virtual CDROM Bus Enumerator; C:\Windows\system32\DRIVERS\CLVirtualBus01.sys []
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [2013-04-22 21712]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2014-03-31 58056]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2014-10-22 164864]
S3 MsgPlusDriver;Messenger Plus! Virtual Camera; C:\Windows\system32\DRIVERS\MsgPlusDriver.sys []
S3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2014-12-11 82816]
S3 PCWinSoft;ScreenCamera Video Camera; C:\Windows\system32\DRIVERS\scrcamhrdrv_x64.sys [2012-10-11 241800]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver; C:\Windows\system32\DRIVERS\SiSG664.sys [2009-06-10 56832]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2014-12-22 16152]
S3 TPM;TPM; C:\Windows\system32\drivers\tpm.sys [2009-07-14 38400]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbser;USB Serial Emulation Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2014-12-28 34816]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2011-11-21 80512]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe [2012-04-13 277120]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [2012-05-31 119424]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 CISVC;@%systemroot%\system32\CISVC.EXE,-1; C:\Windows\system32\CISVC.EXE [2009-07-14 19456]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2014-11-12 2449592]
R2 CLPSLauncher;COMODO LPS Launcher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [2014-12-25 70864]
R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2014-12-09 7618952]
R2 CPMService;COMODO Programs Manager Service; C:\Program Files\COMODO\COMODO Programs Manager\CPMService.exe [2015-01-08 116032]
R2 DragonUpdater;COMODO Dragon Update Service; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2014-11-27 2370240]
R2 GeekBuddyRSP;GeekBuddyRSP Server; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2014-12-25 2327248]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-12-13 1148560]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-12-13 2530640]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2000-01-01 169432]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-12-02 417552]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2000-01-01 390616]
R2 MSMQ;@mqutil.dll,-6102; C:\Windows\system32\mqsvc.exe [2009-07-14 9216]
R2 MySQL;MySQL; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [2013-02-01 12907520]
R2 NetMsmqActivator;Adaptér naslouchání Net.Msmq; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 NetPipeActivator;Adaptér naslouchání Net.Pipe; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-12-13 1701520]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-12-13 19823248]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2014-12-13 935240]
R2 simptcp;@%SystemRoot%\system32\simptcp.dll,-200; C:\Windows\System32\tcpsvcs.exe [2009-07-14 10240]
R2 SNMP;@%SystemRoot%\system32\snmp.exe,-3; C:\Windows\System32\snmp.exe [2010-11-20 49664]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2013-11-01 2324216]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-01-03 5426448]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service; C:\Windows\system32\viakaraokesrv.exe [2000-01-01 27768]
R2 VideoAcceleratorService;VideoAcceleratorService; C:\PROGRA~2\SPEEDB~1\VideoAcceleratorService.exe [2014-02-24 298152]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-08 267440]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-20 107912]
S2 IEEtwCollectorService;Internet Explorer ETW Collector Service; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S2 NetTcpActivator;Adaptér naslouchání Net.Tcp; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-12-11 315496]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2014-12-09 2265304]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-01-29 279000]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-03-31 1512640]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-20 107912]
S3 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2011-05-09 136120]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-12-04 114800]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-03-02 150600]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2014-03-02 5132888]
S3 SystemExplorerHelpService;System Explorer Service; C:\Program Files (x86)\System Explorer\service\SystemExplorerService64.exe [2014-12-20 820960]
S4 NAUpdate;@C:\Program Files (x86)\Nero\Update\NASvc.exe,-200; C:\Program Files (x86)\Nero\Update\NASvc.exe [2014-07-15 786256]

-----------------EOF-----------------

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#10 Příspěvek od Márty84 »

:!: Vypnete antivir, at nebrani programu v praci.
:arrow: Stahnete OTM http://oldtimer.geekstogo.com/OTM.exe a ulozte nejlepe na plochu.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Do leveho okna zkopirujte tento skript (vcetne te dvojtecky pred slovem commands)

Kód: Vybrat vše

:commands
[EMPTYTEMP]
[EMPTYFLASH]
[Purity]
[CreateRestorePoint]

:services
MBAMSwissArmy
AdobeARMservice
AdobeFlashPlayerUpdateSvc
gupdate
SkypeUpdate
gupdatem
gusvc

:files
%windir%\system32\*.tmp.dll /s
%windir%\system32\SET*.tmp /s
%windir%\*.tmp
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job

:reg
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoobzoYouTubeAccelerator] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magic Screenshot.exe] /64
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon] /64
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"DelaypluginInstall"=-
Kliknete na MoveIt a nechte program pracovat. Pri otazce na restart souhlaste.
Po restartu sem dejte log, ktery na vas vyskoci, nebo bude zde C:\_OTM\MovedFiles\xxxxxxxx_xxxxxx (misto tech x budou cisla, predstavujici datum a cas spusteni)
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#11 Příspěvek od rudy630 »

All processes killed
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Classic .NET AppPool
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57311 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: DefaultAppPool
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Guest
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Ruda
->Temp folder emptied: 3178441 bytes
->Temporary Internet Files folder emptied: 1041292 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 29567314 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 58610 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 14029400 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 657672 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 42568363 bytes

Total Files Cleaned = 87,00 mb


[EMPTYFLASH]

User: All Users

User: Classic .NET AppPool
->Flash cache emptied: 0 bytes

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: DefaultAppPool

User: Guest
->Flash cache emptied: 0 bytes

User: Public

User: Ruda
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTM Restore Point
========== SERVICES/DRIVERS ==========
Service MBAMSwissArmy stopped successfully!
Service MBAMSwissArmy deleted successfully!
Service AdobeARMservice stopped successfully!
Service AdobeARMservice deleted successfully!
Service AdobeFlashPlayerUpdateSvc stopped successfully!
Service AdobeFlashPlayerUpdateSvc deleted successfully!
Service gupdate stopped successfully!
Service gupdate deleted successfully!
Service SkypeUpdate stopped successfully!
Service SkypeUpdate deleted successfully!
Service gupdatem stopped successfully!
Service gupdatem deleted successfully!
Service gusvc stopped successfully!
Service gusvc deleted successfully!
========== FILES ==========
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-841361005-909514878-2309378359-1002UA.job moved successfully.
========== REGISTRY ==========
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoobzoYouTubeAccelerator\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GUDelayStartup\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magic Screenshot.exe\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run\\DelaypluginInstall deleted successfully.

OTM by OldTimer - Version 3.1.21.0 log created on 01112015_013358

Files moved on Reboot...
C:\Users\Ruda\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Ruda\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File C:\Windows\temp\officeclicktorun.exe_c2ruidll(201501110049258BC).log not found!
File C:\Windows\temp\officeclicktorun.exe_streamserver(201501110049258BC).log not found!
C:\Windows\temp\RUDA-PC-20150111-0049.log moved successfully.
File move failed. C:\Windows\SysWow64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#12 Příspěvek od Márty84 »

:!: Vsechny tyto programy - vcetne pripadne instalace - spoustejte jako spravce (kliknete na ne pravym mysidlem a zvolte - Spustit jako spravce)

:arrow:
vyosek píše: :arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remote disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner http://www.filehippo.com/download_ccleaner a spustte.
Pri instalaci pozor na toolbar (ci jine doplnky), jestli vam nabidne jeho instalaci, tak zruste zatrzitko.
Po spusteni se ocitnete ve funkci Cistic. Vlevo je spousta zatrzitek. Pozor dejte hlavne na kos, pokud nechate zatrzene, vzdy ho vysype.
Dale, podle toho jak je nastaven, smaze vsechna hesla ulozena na netu!!! Takze jestli mate nastavene, at si pocitac hesla pamatuje (coz neni pro bezpecnost dobre), budete je muset pak napsat znova rucne (napr mail, facebook, ruzna fora atd.)
Kliknete na Analyzovat a az dokonci analyzu, kliknete na Spustit Cleaner.
Potom kliknete vlevo na funkci Registry
Kliknete na Hledej problemy, kdyz najde, kliknete na Opravit problemy. Nabidne Vam zalohu, tu udelejte a ulozte ji tak, at ji v pripade potreby najdete.
Funkce Nastroje umoznuje odinstalovani programu. Je dukladnejsi nez samotny windows!
(Pokud je v pc vice uzivatelskych uctu, pouzijte program i v nich)

:arrow: Defragmentujte disk(y) (SSD Disky ne!)
Stahnete program Defraggler http://www.stahuj.centrum.cz/utility_a_ ... efraggler/
Pri instalaci opet pozor na toolbar a dalsi nesmysly.
Po nainstalovani program spustte a kliknete na Analyzovat, po analyze kliknete na Defragmentovat a programek odvede svou praci.




:arrow: Pak napiste, jak je na tom pc.
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

rudy630
Návštěvník
Návštěvník
Příspěvky: 94
Registrován: 12 říj 2013 14:36

Re: Prosím o radu jak se zbavit AVG

#13 Příspěvek od rudy630 »

Zdravím Vás a chci poděkovat za trpělivost a hlavně za podrobné návody. Bez nich bch nevěděl vůbec "kudy-tudy". Po splnění všech pokynů se jednak uvolnilo dost místa na disku a také se nb zrychlil.
Velké DÍKY!!

Márty84
VIP
VIP
Příspěvky: 21679
Registrován: 05 pro 2009 20:08
Bydliště: Ostrava

Re: Prosím o radu jak se zbavit AVG

#14 Příspěvek od Márty84 »

To jsem rad :)

Nemate zac! ;-)

Mejte se a treba zase nekdy :bye:

:closed:
Pokud máte dotaz, který není určen pro veřejnost, můžete mi napsat na mail marty84zavináčforum.viry.cz

Možnost podpořit naše fórum https://platba.viry.cz/payment/

Z časových důvodů teď budu na fóru méně často. V případě delšího čekání na odpověď kontaktujte prosím některého z kolegů (většina má mailovou adresu ve svém podpisu).

Zamčeno