Stránka 1 z 1

Havěť, přesměrování, vyskakování oken, označování textu zele

Napsal: 21 úno 2015 06:59
od Pettersson
Dobrý den,

omlouvám se, že ruším, ale mám problém s internetem a celkově s PC
Problémy se projevují takto:
Při serfování na internetu se mi otevírají různá okna, sem tam když někam kliknu tak mě to přesměruje zcela jinam. PC ventiluje jak laciná reklama na proudové letadlo. Část textu v chromu mívám nahodile zelenou barvou, s tím, že po kliknutí na text opět přesměrováno. Reklamy ve stránkách stylu cheapCoupon a celkově pomalé odezvy internetu.

Může mi prosím někdo z vás poradit, co a jak s těmi logy nebo co.. ? :(

Prosím moc o pomoc

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 07:28
od Márty84
Zdravim :)

Nejprve dejte log z RSIT (pripadne RSITx64 - podle verze systemu) http://forum.viry.cz/viewtopic.php?f=13&t=130786

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 09:08
od Pettersson
Logfile of random's system information tool 1.10 (written by random/random)
Run by Pettersson at 2015-02-21 08:56:25
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 9 GB (9%) free of 100 GB
Total RAM: 3001 MB (44% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:56:31, on 21.2.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17631)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Pettersson.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... 74A13D0974
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.istartsurf.com/?type=hp&ts=1 ... 74A13D0974
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.istartsurf.com/web/?type=ds& ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.gboxapp.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: VIPRE Search Guard Helper - {963C8283-AE7F-4AA6-9B3B-847A8FC62C5E} - C:\Program Files (x86)\VIPRE\VSGN.dll
O2 - BHO: ShopperProBHO - {A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C} - (no file)
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: HD Streamer - {E6062A33-016E-4BDA-A6F1-890D989F8656} - C:\Program Files (x86)\HD Streamer\ScriptHost.dll (file missing)
O3 - Toolbar: VIPRE Search Guard Toolbar - {A924C17A-5E94-4E02-BED5-49720BA6F7FA} - C:\Program Files (x86)\VIPRE\VSGN.dll
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Salus] C:\Program Files (x86)\Salus\Salus.exe
O4 - HKLM\..\Run: [mncmjfrugSrv] C:\Windows\system32\mncmjfrug.vbe
O4 - HKLM\..\Run: [MSStp] C:\Windows\system32\msstp.vbe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SBAMTray] "C:\Program Files (x86)\VIPRE\SBAMTray.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [LiveSupport] "C:\Program Files (x86)\LiveSupport\LiveSupport.exe" /noshow /log
O4 - HKCU\..\Run: [icq] C:\Users\Pettersson\AppData\Roaming\ICQM\icq.exe -CU
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Viber] "C:\Users\Pettersson\AppData\Local\Viber\Viber.exe"
O4 - HKCU\..\Run: [MilesightVMSLite] "C:\Program Files (x86)\Milesight VMS Lite\Milesight VMS Lite.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Dropbox.lnk = C:\Users\Pettersson\AppData\Roaming\Dropbox\bin\Dropbox.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Odeslat do zařízení Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra 'Tools' menuitem: Odeslat do zařízení &Bluetooth... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra button: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Pettersson\AppData\Roaming\ICQM\icq.exe (HKCU)
O9 - Extra 'Tools' menuitem: ICQ - {086C8477-4F71-4550-87FB-AF0AE8DF3E98} - C:\Users\Pettersson\AppData\Roaming\ICQM\icq.exe (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: vipresg - {47BE2E5B-703B-444F-ABD3-05717D2191C6} - C:\Program Files (x86)\VIPRE\VSGN.dll
O20 - AppInit_DLLs:
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DHCP Server (DHCPServer) - Uwe A. Ruttkamp - C:\Users\PETTER~1\AppData\Local\Temp\Rar$EXa0.284\dhcpsrv.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Enabler Service (EnablerService) - Unknown owner - C:\Program Files (x86)\Addon Enabler\EnablerService.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GFI LanGuard 11 Attendant Service (gfi_lanss11_attservice) - GFI Software Development Ltd. - C:\Program Files (x86)\GFI\LanGuard 11 Agent\lnssatt.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) MPI Library Process Manager, Intel (impi_smpd) - Intel Corporation - C:\Program Files (x86)\Intel\MPI-RT\4.0.3.009\em64t\bin\smpd.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VIPRE Internet Security (SBAMSvc) - ThreatTrack Security Inc. - C:\Program Files (x86)\VIPRE\SBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - ThreatTrack Security Inc. - C:\Program Files (x86)\VIPRE\SBPIMSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Universal Updater Service (UniversalUpdater) - Unknown owner - C:\Program Files (x86)\Universal Updater\UpdaterService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: zjgkutmjvnsxko - LIMITED - c:\windows\SysWOW64\uhffti.exe

--
End of file - 11829 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
C:\Windows\system32\services.exe
winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
c:\windows\SysWOW64\uhffti.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe" /service
"C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe" /service
"taskhost.exe"
"C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
taskeng.exe {838B4DA7-BBB6-45C8-9520-321059968416}
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Users\PETTER~1\AppData\Local\Temp\Rar$EXa0.284\dhcpsrv.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\GFI\LanGuard 11 Agent\lnssatt.exe" -service
"C:\Program Files (x86)\Intel\MPI-RT\4.0.3.009\em64t\bin\smpd.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Windows\System32\igfxtray.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\VIPRE\SBPIMSvc.exe"
"C:\Windows\System32\igfxpers.exe"
C:\Windows\system32\igfxsrvc.exe -Embedding
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe" -start
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"taskhost.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3624.0.1912700485\1782077773" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,18,39 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x2a42 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.1892 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Mixed/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Disabled/QUIC/EnabledWithFecHeaders/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3624.3.939181476\214118052" /prefetch:673131151
taskhost.exe $(Arg0)
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="3624.9.1112872135\688172232" --ppapi-flash-args=enable_hw_video_decode=1 --lang=cs --ignored=" --type=renderer " /prefetch:-632637702
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Mixed/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledWithFecHeaders/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3624.20.940966526\745714415" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Mixed/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledWithFecHeaders/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3624.32.511212322\1347271590" /prefetch:673131151
"C:\Program Files (x86)\Skype\Phone\Skype.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --test-type --enable-deferred-image-decoding --lang=cs --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Mixed/DomRel-Enable/enable/EmbeddedSearch/Group1 dev:pp6 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionContentVerification/ControlEnforce/ExtensionInstallVerification/None/NewProfileManagement/Enabled/OmniboxBundledExperimentV1/DevHQPExperimentsControlR2/PasswordGeneration/Disabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/EnabledWithFecHeaders/RememberCertificateErrorDecisions/Default/SPDY/Spdy4Enabled-default/SRTPromptFieldTrial/On/SafeBrowsingIncidentReportingService/Enabled/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/group_01/UMA-Population-Restrict/normal/UMA-Uniformity-Trial-1-Percent/group_87/UMA-Uniformity-Trial-10-Percent/group_05/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_12/UMA-Uniformity-Trial-50-Percent/default/UwSInterstitialStatus/On/VoiceTrigger/Install/WebRTC-IPv6Default/Enabled/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --extensions-on-chrome-urls --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-accelerated-video-decode --channel="3624.43.909250938\1335670025" /prefetch:673131151

"C:\Users\Pettersson\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default

prefs.js - "browser.startup.homepage" - "http://search.gboxapp.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.11.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.11.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default\extensions\
faststartff@gmail.com
f_qfua@aioyiaa-.co.uk
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre8\bin\ssv.dll [2014-08-12 554920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963C8283-AE7F-4AA6-9B3B-847A8FC62C5E}]
VIPRE Search Guard Helper - C:\Program Files (x86)\VIPRE\x64\VSGNx64.dll [2014-11-20 833424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14 2117216]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre8\bin\jp2ssv.dll [2014-08-12 212904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}]
HD Streamer - C:\Program Files (x86)\HD Streamer\ScriptHost64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963C8283-AE7F-4AA6-9B3B-847A8FC62C5E}]
VIPRE Search Guard Helper - C:\Program Files (x86)\VIPRE\VSGN.dll [2014-11-20 648592]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}]
Skype Click to Call for Internet Explorer - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14 1709152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}]
HD Streamer - C:\Program Files (x86)\HD Streamer\ScriptHost.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A924C17A-5E94-4E02-BED5-49720BA6F7FA} - VIPRE Search Guard Toolbar - C:\Program Files (x86)\VIPRE\x64\VSGNx64.dll [2014-11-20 833424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{A924C17A-5E94-4E02-BED5-49720BA6F7FA} - VIPRE Search Guard Toolbar - C:\Program Files (x86)\VIPRE\VSGN.dll [2014-11-20 648592]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2009-09-02 159232]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2009-09-02 380928]
"Persistence"=C:\Windows\system32\igfxpers.exe [2009-09-02 358912]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06 500208]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"=C:\PROGRA~2\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"LiveSupport"=C:\Program Files (x86)\LiveSupport\LiveSupport.exe /noshow /log []
"icq"=C:\Users\Pettersson\AppData\Roaming\ICQM\icq.exe [2014-03-12 33664344]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]
"Viber"=C:\Users\Pettersson\AppData\Local\Viber\Viber.exe []
"MilesightVMSLite"=C:\Program Files (x86)\Milesight VMS Lite\Milesight VMS Lite.exe [2014-08-12 1777664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 1022152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync]
C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2010-03-13 112512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CorelDRAW Graphics Suite 11b]
C:\Program Files (x86)\Corel\Corel Graphics 12\Languages\CZ\Programs\Registration.exe [2004-06-23 729088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-03-14 3672640]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\icq]
C:\Users\Pettersson\AppData\Roaming\ICQM\icq.exe [2014-03-12 33664344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mnchggjaSrv]
C:\Windows\system32\mnchggja.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSStp]
C:\Windows\inf\msstp.vbe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-06-16 224128]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vpngui.exe.lnk]
C:\Windows\Installer\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}\Icon09DB8A851.exe [2014-03-19 5120]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"=C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"Salus"=C:\Program Files (x86)\Salus\Salus.exe []
"mncmjfrugSrv"=C:\Windows\system32\mncmjfrug.vbe []
"MSStp"=C:\Windows\system32\msstp.vbe []
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2011-10-24 421888]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS5ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [2010-02-22 406992]
"SBAMTray"=C:\Program Files (x86)\VIPRE\SBAMTray.exe [2014-11-20 2887568]

C:\Users\Pettersson\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Dropbox.lnk - C:\Users\Pettersson\AppData\Roaming\Dropbox\bin\Dropbox.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=" "

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2009-09-02 259584]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBPIMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBAMSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SBPIMSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpid.exe"="C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpid.exe:LocalSubNet:Enabled:mpid.exe"
"C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpirun.exe"="C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpirun.exe:LocalSubNet:Enabled:mpirun.exe"
"C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpidiag.exe"="C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpidiag.exe:LocalSubNet:Enabled:mpidiag.exe"
"C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpisrvutil.exe"="C:\Program Files (x86)\Platform Computing\Platform-MPI\bin\mpisrvutil.exe:LocalSubNet:Enabled:mpisrvutil.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux1"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-02-21 08:56:26 ----D---- C:\Program Files\trend micro
2015-02-21 08:56:25 ----D---- C:\rsit
2015-02-15 10:34:01 ----D---- C:\Program Files (x86)\EAGLE-6.5.0
2015-02-15 09:33:05 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2015-02-15 09:33:05 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2015-02-15 09:33:04 ----A---- C:\Windows\system32\jscript9diag.dll
2015-02-15 09:33:04 ----A---- C:\Windows\system32\jscript9.dll
2015-02-15 09:30:23 ----A---- C:\Windows\SYSWOW64\IJL_11.DLL
2015-02-11 00:34:52 ----A---- C:\Windows\system32\generaltel.dll
2015-02-11 00:34:52 ----A---- C:\Windows\system32\appraiser.dll
2015-02-11 00:34:52 ----A---- C:\Windows\system32\aeinv.dll
2015-02-11 00:34:51 ----A---- C:\Windows\system32\invagent.dll
2015-02-11 00:34:51 ----A---- C:\Windows\system32\devinv.dll
2015-02-11 00:34:51 ----A---- C:\Windows\system32\aitstatic.exe
2015-02-11 00:34:50 ----A---- C:\Windows\system32\aepic.dll
2015-02-11 00:34:50 ----A---- C:\Windows\system32\aepdu.dll
2015-02-11 00:34:38 ----A---- C:\Windows\system32\schannel.dll
2015-02-11 00:34:37 ----A---- C:\Windows\SYSWOW64\schannel.dll
2015-02-11 00:34:36 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2015-02-11 00:34:35 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2015-02-11 00:34:35 ----A---- C:\Windows\system32\kerberos.dll
2015-02-11 00:34:34 ----A---- C:\Windows\system32\wdigest.dll
2015-02-11 00:34:34 ----A---- C:\Windows\system32\ncrypt.dll
2015-02-11 00:34:34 ----A---- C:\Windows\system32\msv1_0.dll
2015-02-11 00:34:33 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2015-02-11 00:34:33 ----A---- C:\Windows\system32\TSpkg.dll
2015-02-11 00:34:32 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2015-02-11 00:34:30 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2015-02-11 00:34:28 ----A---- C:\Windows\SYSWOW64\credssp.dll
2015-02-11 00:34:28 ----A---- C:\Windows\system32\credssp.dll
2015-02-11 00:34:07 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2015-02-11 00:34:07 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2015-02-11 00:34:06 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2015-02-11 00:34:06 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-02-11 00:34:06 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-02-11 00:34:05 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2015-02-11 00:34:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2015-02-11 00:34:04 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2015-02-11 00:34:04 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2015-02-11 00:34:04 ----A---- C:\Windows\system32\iernonce.dll
2015-02-11 00:34:04 ----A---- C:\Windows\system32\ie4uinit.exe
2015-02-11 00:34:03 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2015-02-11 00:34:03 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 00:34:02 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2015-02-11 00:34:01 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2015-02-11 00:33:59 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2015-02-11 00:33:59 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2015-02-11 00:33:58 ----A---- C:\Windows\system32\urlmon.dll
2015-02-11 00:33:58 ----A---- C:\Windows\system32\iedkcs32.dll
2015-02-11 00:33:57 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2015-02-11 00:33:57 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 00:33:56 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2015-02-11 00:33:56 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2015-02-11 00:33:55 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 00:33:54 ----A---- C:\Windows\SYSWOW64\ieui.dll
2015-02-11 00:33:54 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2015-02-11 00:33:54 ----A---- C:\Windows\system32\msfeeds.dll
2015-02-11 00:33:54 ----A---- C:\Windows\system32\dxtrans.dll
2015-02-11 00:33:53 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2015-02-11 00:33:52 ----A---- C:\Windows\system32\iesetup.dll
2015-02-11 00:33:52 ----A---- C:\Windows\system32\ieapfltr.dll
2015-02-11 00:33:50 ----A---- C:\Windows\system32\iertutil.dll
2015-02-11 00:33:49 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2015-02-11 00:33:48 ----A---- C:\Windows\SYSWOW64\wininet.dll
2015-02-11 00:33:48 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2015-02-11 00:33:47 ----A---- C:\Windows\system32\jsproxy.dll
2015-02-11 00:33:47 ----A---- C:\Windows\system32\ieUnatt.exe
2015-02-11 00:33:46 ----A---- C:\Windows\SYSWOW64\msrating.dll
2015-02-11 00:33:45 ----A---- C:\Windows\system32\ieui.dll
2015-02-11 00:33:45 ----A---- C:\Windows\system32\dxtmsft.dll
2015-02-11 00:33:44 ----A---- C:\Windows\system32\ieframe.dll
2015-02-11 00:33:43 ----A---- C:\Windows\system32\mshtmled.dll
2015-02-11 00:33:42 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-02-11 00:33:41 ----A---- C:\Windows\system32\vbscript.dll
2015-02-11 00:33:40 ----A---- C:\Windows\system32\wininet.dll
2015-02-11 00:33:39 ----A---- C:\Windows\system32\msrating.dll
2015-02-11 00:33:39 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-02-11 00:33:36 ----A---- C:\Windows\system32\mshtml.dll
2015-02-11 00:33:09 ----A---- C:\Windows\system32\WindowsCodecs.dll
2015-02-11 00:33:07 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2015-02-11 00:32:59 ----A---- C:\Windows\system32\lsasrv.dll
2015-02-11 00:32:58 ----A---- C:\Windows\system32\drivers\cng.sys
2015-02-11 00:32:57 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2015-02-11 00:32:57 ----A---- C:\Windows\system32\adtschema.dll
2015-02-11 00:32:56 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2015-02-11 00:32:56 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2015-02-11 00:32:55 ----A---- C:\Windows\system32\sspicli.dll
2015-02-11 00:32:55 ----A---- C:\Windows\system32\auditpol.exe
2015-02-11 00:32:54 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2015-02-11 00:32:54 ----A---- C:\Windows\system32\sspisrv.dll
2015-02-11 00:32:54 ----A---- C:\Windows\system32\secur32.dll
2015-02-11 00:32:54 ----A---- C:\Windows\system32\lsass.exe
2015-02-11 00:32:53 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2015-02-11 00:32:53 ----A---- C:\Windows\SYSWOW64\secur32.dll
2015-02-11 00:32:53 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2015-02-11 00:32:53 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2015-02-11 00:32:53 ----A---- C:\Windows\system32\msobjs.dll
2015-02-11 00:32:53 ----A---- C:\Windows\system32\msaudite.dll
2015-02-11 00:32:43 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2015-02-11 00:32:43 ----A---- C:\Windows\system32\crypt32.dll
2015-02-11 00:32:38 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2015-02-11 00:32:38 ----A---- C:\Windows\system32\oleaut32.dll
2015-02-11 00:32:33 ----A---- C:\Windows\system32\mstscax.dll
2015-02-11 00:32:31 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2015-02-11 00:32:28 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2015-02-11 00:32:04 ----A---- C:\Windows\SYSWOW64\scesrv.dll
2015-02-11 00:32:04 ----A---- C:\Windows\system32\scesrv.dll
2015-02-11 00:31:55 ----A---- C:\Windows\system32\ntoskrnl.exe
2015-02-11 00:31:52 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2015-02-11 00:31:52 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2015-02-11 00:31:49 ----A---- C:\Windows\system32\srcore.dll
2015-02-11 00:31:49 ----A---- C:\Windows\system32\rstrui.exe
2015-02-11 00:31:46 ----A---- C:\Windows\system32\srclient.dll
2015-02-11 00:31:45 ----A---- C:\Windows\SYSWOW64\srclient.dll
2015-02-11 00:31:23 ----A---- C:\Windows\system32\win32k.sys
2015-02-06 09:45:51 ----D---- C:\Program Files (x86)\Platform Computing
2015-02-06 08:34:05 ----D---- C:\Program Files\AnsysEM
2015-02-05 19:23:12 ----A---- C:\Windows\SYSWOW64\FlashPlayerInstaller.exe
2015-01-25 11:53:40 ----A---- C:\Windows\system32\SBRC.dat
2015-01-25 11:53:11 ----A---- C:\Windows\system32\drivers\gfiutil.sys
2015-01-25 11:53:10 ----A---- C:\Windows\system32\drivers\gfiark.sys
2015-01-25 11:45:42 ----A---- C:\Windows\system32\drivers\sbhips.sys
2015-01-25 11:45:38 ----A---- C:\Windows\system32\sbbd.exe
2015-01-25 11:45:33 ----D---- C:\Windows\SYSWOW64\System32
2015-01-25 11:45:33 ----D---- C:\ProgramData\GFI
2015-01-25 11:45:33 ----D---- C:\Program Files (x86)\GFI
2015-01-25 11:45:32 ----D---- C:\ProgramData\VIPRE
2015-01-25 11:39:44 ----D---- C:\Program Files (x86)\VIPRE
2015-01-25 11:39:30 ----D---- C:\Users\Pettersson\AppData\Roaming\VIPRE

======List of files/folders modified in the last 1 month======

2015-02-21 08:56:31 ----D---- C:\Windows\Prefetch
2015-02-21 08:56:29 ----D---- C:\Windows\Temp
2015-02-21 08:56:26 ----RD---- C:\Program Files
2015-02-21 08:38:00 ----D---- C:\Users\Pettersson\AppData\Roaming\Skype
2015-02-21 04:38:39 ----D---- C:\Windows\system32\config
2015-02-21 04:29:29 ----SHD---- C:\Windows\Installer
2015-02-21 04:29:28 ----HD---- C:\Config.Msi
2015-02-21 04:29:27 ----D---- C:\Program Files (x86)\Common Files
2015-02-21 04:28:06 ----SHD---- C:\System Volume Information
2015-02-21 04:26:30 ----D---- C:\Users\Pettersson\AppData\Roaming\Dropbox
2015-02-21 04:24:10 ----HD---- C:\Program Files (x86)\Vtthudpvrrr
2015-02-21 04:23:38 ----D---- C:\Windows\SysWOW64
2015-02-21 04:23:29 ----AD---- C:\Windows\System32
2015-02-20 17:15:48 ----D---- C:\ProgramData\Skype
2015-02-20 17:15:47 ----RD---- C:\Program Files (x86)\Skype
2015-02-20 15:53:20 ----D---- C:\Program Files (x86)\TeamViewer
2015-02-20 15:53:19 ----D---- C:\Windows\system32\Tasks
2015-02-18 11:48:16 ----D---- C:\Windows\system32\catroot2
2015-02-16 13:48:12 ----D---- C:\Windows\inf
2015-02-16 13:48:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-02-16 06:09:27 ----D---- C:\Windows\rescache
2015-02-15 13:21:58 ----AD---- C:\ProgramData\TEMP
2015-02-15 12:32:06 ----D---- C:\Windows\winsxs
2015-02-15 12:32:00 ----D---- C:\Windows\SYSWOW64\en-US
2015-02-15 12:31:59 ----D---- C:\Windows\system32\en-US
2015-02-15 10:34:01 ----RD---- C:\Program Files (x86)
2015-02-12 06:48:02 ----D---- C:\ProgramData\ChampionDeals
2015-02-11 07:37:02 ----RSD---- C:\Windows\Fonts
2015-02-11 03:24:12 ----SD---- C:\Windows\system32\CompatTel
2015-02-11 03:24:11 ----D---- C:\Windows\system32\cs-CZ
2015-02-11 03:24:11 ----D---- C:\Windows\system32\appraiser
2015-02-11 03:24:10 ----D---- C:\Program Files\Internet Explorer
2015-02-11 03:24:09 ----D---- C:\Windows\SYSWOW64\cs-CZ
2015-02-11 03:24:07 ----D---- C:\Program Files (x86)\Internet Explorer
2015-02-11 03:24:05 ----D---- C:\Windows\system32\drivers
2015-02-11 03:24:00 ----D---- C:\Windows\PolicyDefinitions
2015-02-06 17:15:25 ----D---- C:\Windows\system32\NDF
2015-02-06 09:42:52 ----D---- C:\Program Files (x86)\Intel
2015-02-06 09:30:10 ----D---- C:\Program Files\Common Files\Microsoft Shared
2015-02-06 08:26:42 ----D---- C:\Users\Pettersson\AppData\Roaming\vlc
2015-02-05 19:23:25 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2015-02-01 16:19:22 ----D---- C:\Windows\Tasks
2015-01-25 11:46:21 ----D---- C:\Windows\Microsoft.NET
2015-01-25 11:45:33 ----HD---- C:\ProgramData

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-21 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-03-07 283200]
R1 TsLwWfF;WiFi Capture Driver; C:\Windows\system32\DRIVERS\TsLwWfF.sys [2012-03-26 26728]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2014-09-15 42696]
R2 sbapifs;sbapifs; C:\Windows\system32\DRIVERS\sbapifs.sys [2014-11-20 88928]
R3 BCM43XX;Broadcom 802.11 – ovladač síťového adaptéru; C:\Windows\system32\DRIVERS\bcmwl664.sys [2009-06-10 1311232]
R3 CVPNDRVA;Cisco Systems Inc. IPSec Driver; \??\C:\Windows\system32\Drivers\CVPNDRVA.sys [2011-03-04 306536]
R3 DNE;Deterministic Network Enhancer Miniport; C:\Windows\system32\DRIVERS\dne64x.sys [2008-11-16 157968]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2009-09-02 7369728]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-06-10 57344]
S1 sbwfw;sbwfw; C:\Windows\system32\DRIVERS\sbwfw.sys [2014-11-20 345392]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2014-09-15 310984]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 athr;Atheros – ovladač pro zařízení pro rozšiřitelnou bezdrátovou síť LAN; C:\Windows\system32\DRIVERS\athrx.sys [2009-06-20 1394688]
S3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 CVirtA;Cisco Systems VPN Adapter for 64-bit Windows; C:\Windows\system32\DRIVERS\CVirtA64.sys [2010-02-08 14992]
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys [2010-11-21 71168]
S3 FTDIBUS;USB Serial Converter Driver; C:\Windows\system32\drivers\ftdibus.sys [2014-01-31 94704]
S3 FTSER2K;USB Serial Port Driver; C:\Windows\system32\drivers\ftser2k.sys [2014-01-31 86896]
S3 gfiark;gfiark; C:\Windows\system32\drivers\gfiark.sys [2013-05-23 41032]
S3 gfiutil;gfiutil; C:\Windows\system32\drivers\gfiutil.sys [2013-09-04 31264]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-21 165888]
S3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-21 6656]
S3 sbhips;sbhips; C:\Windows\system32\drivers\sbhips.sys [2014-11-20 63696]
S3 sbwtis;sbwtis; C:\Windows\system32\DRIVERS\sbwtis.sys [2014-11-20 95608]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\sscdbus.sys [2010-11-11 136264]
S3 sscdmdfl;SAMSUNG Mobile Modem Filter; C:\Windows\system32\DRIVERS\sscdmdfl.sys [2010-11-11 19016]
S3 sscdmdm;SAMSUNG Mobile Modem Drivers; C:\Windows\system32\DRIVERS\sscdmdm.sys [2010-11-11 172104]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-21 34688]
S3 teamviewervpn;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2013-09-11 35112]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Serial emulation modem driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys [2010-11-21 199552]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-21 21760]
S3 VSPerfDrv110;Performance Tools Driver 11.0; \??\C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [2012-07-13 70264]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 WinDriver6;WinDriver6; C:\Windows\system32\drivers\windrvr6.sys [2014-04-28 268800]
S3 WinUsb;YunOS USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 WSDPrintDevice;Podpora tisku WSD prostřednictvím funkce UMB; C:\Windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 c2cautoupdatesvc;Skype Click to Call Updater; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-07-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-07-14 1767520]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 CVPND;Cisco Systems, Inc. VPN Service; C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe [2011-03-04 1529856]
R2 DHCPServer;DHCP Server; C:\Users\PETTER~1\AppData\Local\Temp\Rar$EXa0.284\dhcpsrv.exe [2013-02-22 110592]
R2 gfi_lanss11_attservice;GFI LanGuard 11 Attendant Service; C:\Program Files (x86)\GFI\LanGuard 11 Agent\lnssatt.exe [2012-11-23 133496]
R2 impi_smpd;Intel(R) MPI Library Process Manager, Intel; C:\Program Files (x86)\Intel\MPI-RT\4.0.3.009\em64t\bin\smpd.exe [2011-08-24 1611168]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 SBPIMSvc;SB Recovery Service; C:\Program Files (x86)\VIPRE\SBPIMSvc.exe [2014-11-20 177040]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2012-02-11 129624]
R2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-02-17 5436176]
R3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 EnablerService;Enabler Service; C:\Program Files (x86)\Addon Enabler\EnablerService.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-30 116648]
S2 SBAMSvc;VIPRE Internet Security; C:\Program Files (x86)\VIPRE\SBAMSvc.exe [2014-11-20 3963240]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-01-02 315488]
S2 UniversalUpdater;Universal Updater Service; C:\Program Files (x86)\Universal Updater\UpdaterService.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05 267440]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2014-03-09 647680]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-04-30 116648]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-01-12 114688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [2012-07-25 126976]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-03-09 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]

-----------------EOF-----------------

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 09:09
od Pettersson
Zde je log, moc děkuji za pomoc

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 13:25
od Márty84
Je tam toho dost. Doufam, ze mate zalohovana data.


:arrow: Stahnete AdwCleaner https://toolslib.net/downloads/finish/1/ a ulozte ho na plochu.
Ukoncete vsechny programy, jinak to AdwCleaner udela za vas.
Kliknete na nej pravym mysidlem a levym na Spustit jako spravce.
Kliknete na Scan a pockejte, az kontrola dobehne.
Pak kliknete na Clean
Program zacne pracovat (muze dojit k restartu pc) a vyplivne log (pripadne bude zde C:\AdwCleaner\AdwCleaner [S?].txt ). Ten mi sem zkopirujte.


:arrow: Udelejte kontrolu s MBAM. Test nastavte podle tohoto navodu http://forum.viry.cz/viewtopic.php?f=29&t=137928 a dejte sem vysledky. Predem nic nemazte, miva obcas falesne detekce

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 14:13
od Pettersson
# AdwCleaner v4.111 - Logfile created 21/02/2015 at 14:05:57
# Updated 18/02/2015 by Xplode
# Database : 2015-02-18.3 [Server]
# Operating system : Windows 7 Professional Service Pack 1 (x64)
# Username : Pettersson - PETTERSSON-PC
# Running from : C:\Users\Pettersson\Downloads\adwcleaner_4.111.exe
# Option : Cleaning

***** [ Services ] *****

[#] Service Deleted : EnablerService
[#] Service Deleted : UniversalUpdater

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\374311380
Folder Deleted : C:\ProgramData\IePluginServices
Folder Deleted : C:\ProgramData\WindowsMangerProtect
Folder Deleted : C:\ProgramData\ChampionDeals
Folder Deleted : C:\ProgramData\savvinshop
Folder Deleted : C:\ProgramData\a8dccd190a131b22
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\uc
Folder Deleted : C:\Program Files (x86)\uc
Folder Deleted : C:\Users\PETTER~1\AppData\Local\Temp\PodoWeb
Folder Deleted : C:\Users\Pettersson\AppData\Local\globalUpdate
Folder Deleted : C:\Users\Pettersson\AppData\Local\HD Streamer
Folder Deleted : C:\Users\Pettersson\AppData\Local\CrashRpt
Folder Deleted : C:\Users\Pettersson\Documents\Optimizer Pro
Folder Deleted : C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default\Extensions\faststartff@gmail.com
Folder Deleted : C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Folder Deleted : C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default\Extensions\f_qfua@aioyiaa-.co.uk
File Deleted : C:\Users\Pettersson\AppData\Roaming\LiveSupport.exe_log.txt
File Deleted : C:\Users\Pettersson\AppData\Roaming\regsvr32.exe_log.txt
File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\istartsurf.xml
File Deleted : C:\Users\Pettersson\AppData\Roaming\Mozilla\Firefox\Profiles\je4g6vf4.default\user.js

***** [ Scheduled tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [faststartff@gmail.com]
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [livesupport]
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.BackgroundHostObject
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.BackgroundHostObject.1
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.ScriptHostObject
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.ScriptHostObject.1
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.Tool
Key Deleted : HKLM\SOFTWARE\Classes\HD Streamer.Tool.1
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Salus]
Key Deleted : HKCU\Software\Mozilla\Extends
Key Deleted : HKLM\SOFTWARE\Classes\savinshop.savinshop
Key Deleted : HKLM\SOFTWARE\Classes\savinshop.savinshop.2.3
Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{33E06582-221E-400F-809B-30D3984DB355}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6D1D50BF-286D-9728-EF9C-7E6FDDBBEAE4}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5375FB9F-DF09-444B-9DC0-C6ED079C2577}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{73BB74C6-8886-4245-BCDA-448137D75D42}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6D1D50BF-286D-9728-EF9C-7E6FDDBBEAE4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6D1D50BF-286D-9728-EF9C-7E6FDDBBEAE4}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A5A51D2A-505A-4D84-AFC6-E0FA87E47B8C}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6D1D50BF-286D-9728-EF9C-7E6FDDBBEAE4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{33E06582-221E-400F-809B-30D3984DB355}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CACBAC2D-FDC3-4608-A289-6F281F471B83}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{6D1D50BF-286D-9728-EF9C-7E6FDDBBEAE4}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03C0AC00-86DE-4B55-81BA-2E7CD61C51B1}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6062A33-016E-4BDA-A6F1-890D989F8656}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Key Deleted : HKCU\Software\Goobzo
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\SupHpUISoft
Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\iWebar
Key Deleted : HKCU\Software\AppDataLow\Software\Sense
Key Deleted : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Key Deleted : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Key Deleted : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Key Deleted : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Key Deleted : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Key Deleted : HKLM\SOFTWARE\Goobzo
Key Deleted : HKLM\SOFTWARE\istartsurfSoftware
Key Deleted : HKLM\SOFTWARE\iWebar
Key Deleted : HKLM\SOFTWARE\Sense
Key Deleted : HKLM\SOFTWARE\SupDp
Key Deleted : HKLM\SOFTWARE\SupTab
Key Deleted : HKLM\SOFTWARE\supWindowsMangerProtect
Key Deleted : HKLM\SOFTWARE\supWPM
Key Deleted : HKLM\SOFTWARE\Salus
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{70BD2558-27DA-8B02-02D0-D8704ECD2EDF}
Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istartsurf.com

***** [ Web browsers ] *****

-\\ Internet Explorer v11.0.9600.17631

Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

-\\ Mozilla Firefox v31.0 (x86 cs)

[je4g6vf4.default\prefs.js] - Line Deleted : user_pref("browser.search.defaultenginename", "istartsurf");
[je4g6vf4.default\prefs.js] - Line Deleted : user_pref("browser.startup.homepage", "hxxp://search.gboxapp.com/");
[je4g6vf4.default\prefs.js] - Line Deleted : user_pref("extensions.crossrider.bic", "147e2e26626227cb282c463a6d3911bf");

-\\ Google Chrome v40.0.2214.94


*************************

AdwCleaner[R0].txt - [11793 bytes] - [21/02/2015 14:03:52]
AdwCleaner[S0].txt - [10430 bytes] - [21/02/2015 14:05:57]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [10490 bytes] ##########

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 14:14
od Pettersson
Toto je log ze souboru AdwCleaner[S0]
Teď jdu na to druhé, jinak cheapcoupon sv*inka tam je stále, jdu na to druhé tedy... ;)
Děkuji

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 21 úno 2015 15:41
od Márty84
Nejde to vyhodit vsechno najednou :)

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 22 úno 2015 18:26
od Pettersson
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 22.2.2015
Scan Time: 14:47:08
Logfile: Mbam.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.02.22.03
Rootkit Database: v2015.02.20.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Pettersson

Scan Type: Custom Scan
Result: Completed
Objects Scanned: 1031211
Time Elapsed: 3 hr, 34 min, 32 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 6
PUP.Optional.AppsHat.A, HKLM\SOFTWARE\Apps Hat-nv, , [5b20eb36e8a237ff675da62532d1b54b],
PUP.Optional.AppsHat.A, HKLM\SOFTWARE\WOW6432NODE\Apps Hat-nv, , [e19ad64b3e4c7fb77b494f7c38cb8d73],
PUP.Optional.AppsHat.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Apps Hat, , [25567da4a4e63501826115c30ff4ed13],
PUP.Optional.iWebar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [dc9fff2273171b1bcb49a2f79370d030],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [0b703be6404a87af46a69ed5ff04f010],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 5
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\bitstreams, , [8eed1d049befe056ae5dbf9e0df6758b],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703, , [86f5d24f18723bfbeefe1a59da297090],

Files: 48
PUP.Optional.Somoto.A, C:\Users\Pettersson\AppData\Local\Temp\appshat_generic.exe, , [f784f32ee9a1d85e7f260b179070916f],
PUP.Optional.Installcore, C:\Users\Pettersson\AppData\Local\Temp\PartnerInstaller_smtyc.exe, , [f7843de48bff34028d074eaabc463fc1],
PUP.Optional.WindowsProtectManger.A, C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir, , [0a71a180f2983afc6294a228758c8080],
PUP.Optional.OpenCandy, D:\Programy\DTLite4471-0333.exe, , [25561c05d3b737ffa56b00f11de8d12f],
Malware.Trace, C:\Windows\inf\ntvdm.inf, , [6d0e26fbd3b72511a8999e5a21e38977],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\diablo130302.cl, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\diakgcn121016.cl, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\libcurl-4.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\libeay32.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\libidn-11.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\librtmp.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\libssh2.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\phatk121016.cl, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\poclbm130302.cl, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\scrypt130511.cl, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\ssleay32.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\zlib1.dll, , [8eed1d049befe056ae5dbf9e0df6758b],
Trojan.Agent.BCM, C:\Windows\inf\mncqaesb\bitstreams\fpgaminer_top_fixed7_197MHz.ncd, , [8eed1d049befe056ae5dbf9e0df6758b],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\GoogleCrashHandler.exe, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\GoogleUpdate.exe, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\GoogleUpdateBroker.exe, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\GoogleUpdateHelper.msi, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\GoogleUpdateOnDemand.exe, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\goopdate.dll, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\goopdateres_en.dll, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\npGoogleUpdate4.dll, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\psmachine.dll, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.184078\psuser.dll, , [0b703be6404a87af46a69ed5ff04f010],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\GoogleCrashHandler.exe, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\GoogleUpdate.exe, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\GoogleUpdateBroker.exe, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\GoogleUpdateHelper.msi, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\GoogleUpdateOnDemand.exe, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\goopdate.dll, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\goopdateres_en.dll, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\npGoogleUpdate4.dll, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\psmachine.dll, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.225233\psuser.dll, , [fa81958cc6c455e109e33241669d4bb5],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\GoogleCrashHandler.exe, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\GoogleUpdate.exe, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\GoogleUpdateBroker.exe, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\GoogleUpdateHelper.msi, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\GoogleUpdateOnDemand.exe, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\goopdate.dll, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\goopdateres_en.dll, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\npGoogleUpdate4.dll, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\psmachine.dll, , [86f5d24f18723bfbeefe1a59da297090],
PUP.Optional.GlobalUpdate.A, C:\Users\Pettersson\AppData\Local\Temp\comh.270703\psuser.dll, , [86f5d24f18723bfbeefe1a59da297090],

Physical Sectors: 0
(No malicious items detected)


(end)

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 22 úno 2015 18:28
od Pettersson
Zdravím, tak tedy o zprávu zpět je uveden log z MBAM, omlouvám se, že to je tak dlouho, ale musel jsem do práce a zapoměl jsem to zapnout a dneska to trvalo poženahně dlho

Předem moc děkuji za odpověď co dál

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 22 úno 2015 20:42
od Márty84
Nic se nedeje, ja taky nejsem u pocitace porad. Je to jen nas konicek :)


:arrow: Vsechny nalezy hodte do karanteny. Po restartu pc musite test zopakovat, at vime, jestli se to nevraci. Napiste vysledek testu a podle nej zvolim dalsi postup.

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 23 úno 2015 16:44
od Pettersson
A dají se někde prosím najít ty výsledky nebo nějak pracovat s tím logem? Nebo musím scanovat znovu jen proto abych to mohl smazat, páč to trvalo věčnost..

Re: Havěť, přesměrování, vyskakování oken, označování textu

Napsal: 23 úno 2015 18:10
od Márty84
Pokud jste MBAM pred vymazanim haveti zavrel, nezbyva, nez test zopakovat. Pak nalezy odstranit, restartovat pc a udelat dalsi test, aby se overilo, jestli se to nevraci treba z bodu obnovy.




29.3. pro neaktivitu :lock: http://forum.viry.cz/viewtopic.php?f=12&t=123975