Chrome - malware omniboxes
Napsal: 11 bře 2015 16:46
Dobrý den, nějakým způsobem se mi do pc dostal omniboxes, prosím o kontrolu logu z FRST a radu co s tím.. Log Addition v příloze.
Díky za odpověď.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Miroslav (administrator) on PC-KANCELAR on 11-03-2015 16:40:21
Running from C:\Users\Miroslav\Desktop
Loaded Profiles: Miroslav (Available profiles: Miroslav)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
(razercfg MFC Application) C:\Program Files (x86)\Razer\Lachesis\OSD.exe
() C:\Program Files (x86)\Razer\Lachesis\razertra.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Ghisler Software GmbH) C:\Program Files\TotalCMD\TOTALCMD64.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Miroslav\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2014-01-07] (Hewlett-Packard )
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2014-01-07] (IDT, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2015-02-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-01-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-14] (InstallShield Software Corporation)
HKLM-x32\...\Run: [Lachesis] => C:\Program Files (x86)\Razer\Lachesis\razerhid.exe [248320 2009-11-10] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-14] (InstallShield Software Corporation)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [GoogleChromeAutoLaunch_32355425123F7F9C052AB58FA7004C44] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [809288 2015-03-07] (Google Inc.)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Policies\Explorer: []
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\MountPoints2: {bcdf6e9e-43ae-11e4-8267-a0d3c13f7eff} - "G:\HTC_Sync_Manager_PC.exe"
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll (Autodesk, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKLM -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {EE804AE7-BB17-460D-8D8D-EB05F6A35E55} URL = https://search.yahoo.com/search?fr=chr- ... earchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-11] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-30] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-30] (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{D8B99B1A-27EA-46D5-877A-68647B777EB8}: [NameServer] 10.0.0.138
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.omniboxes.com/?type=sc&ts=14 ... 1794401479
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-09] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-09] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll No File
Chrome:
=======
CHR HomePage: Profile 1 -> https://www.google.cz/
CHR StartupUrls: Profile 1 -> "hxxp://google.cz/"
CHR DefaultSuggestURL: Profile 1 -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Translate) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-01-05]
CHR Extension: (Google Drive) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-05]
CHR Extension: (YouTube) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-05]
CHR Extension: (Google Search) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-05]
CHR Extension: (Google Sheets) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-05]
CHR Extension: (Page Analytics (by Google)) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fnbdnhhicmebfgdgglcdacdapkcihcoh [2015-01-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-01-05]
CHR Extension: (AdBlock) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-05]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2015-01-05]
CHR Extension: (Dropbox) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2015-01-05]
CHR Extension: (Type Sample) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jobccjjaffckfoggljonehppmldgmkmh [2015-02-27]
CHR Extension: (Wordpress Admin Bar Control) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\joldejophkhmeajgjenfnfdpfjkalckn [2015-01-20]
CHR Extension: (Převod měn) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjehaadplpgckpgeoddpnijogjaldela [2015-01-05]
CHR Extension: (Google Maps) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-01-05]
CHR Extension: (Google Mail Checker) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-01-05]
CHR Extension: (Hangouts) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-01-05]
CHR Extension: (Save to Pocket) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2015-01-06]
CHR Extension: (Google Wallet) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-05]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2015-03-02]
CHR Extension: (Gmail) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe [56648 2015-02-01] (Google Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-12] (Intel Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [340480 2014-01-07] (IDT, Inc.) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
S2 Update Air Globe; "C:\Program Files (x86)\Air Globe\updateAirGlobe.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [293888 2014-11-28] (Alcohol Soft Development Team)
S3 lachesis35g; C:\Windows\System32\drivers\lachesis35g.sys [11776 2012-12-10] (Razer USA Ltd) [File not signed]
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-12] (Intel Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-08-04] (Duplex Secure Ltd.)
R3 VaneFltr; C:\Windows\system32\drivers\Lachesis.sys [29952 2009-10-16] (Razer (Asia-Pacific) Pte Ltd)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mcpltsvc; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 16:40 - 2015-03-11 16:40 - 00023235 _____ () C:\Users\Miroslav\Desktop\FRST.txt
2015-03-11 16:39 - 2015-03-11 16:40 - 00000000 ____D () C:\FRST
2015-03-11 16:37 - 2015-03-11 16:37 - 00112640 _____ (forum.viry.cz) C:\Users\Miroslav\Desktop\FRSTLauncher.exe
2015-03-11 16:35 - 2015-03-11 16:35 - 02095616 _____ (Farbar) C:\Users\Miroslav\Desktop\FRST64.exe
2015-03-11 16:29 - 2015-03-11 16:29 - 00388608 _____ (Trend Micro Inc.) C:\Users\Miroslav\Downloads\hijackthis.exe
2015-03-11 16:29 - 2015-03-11 16:29 - 00010296 _____ () C:\Users\Miroslav\Downloads\hijackthis.log
2015-03-11 16:21 - 2015-03-11 16:21 - 01720017 _____ () C:\Users\Miroslav\Desktop\Romotop_KV662.skp
2015-03-11 16:10 - 2015-03-11 16:10 - 01272937 _____ () C:\Users\Miroslav\Downloads\kv662.skp
2015-03-11 16:10 - 2015-03-11 16:10 - 01083835 _____ () C:\Users\Miroslav\Desktop\prislusenstvi.rar
2015-03-11 15:42 - 2015-03-11 15:44 - 00000000 ____D () C:\AdwCleaner
2015-03-11 15:31 - 2015-03-11 15:32 - 00000000 ____D () C:\Users\Miroslav\Desktop\kv
2015-03-11 15:31 - 2015-03-11 15:31 - 00000788 _____ () C:\windows\setupact.log
2015-03-11 15:31 - 2015-03-11 15:31 - 00000000 _____ () C:\windows\setuperr.log
2015-03-11 15:24 - 2015-03-11 15:25 - 02171392 _____ () C:\Users\Miroslav\Desktop\adwcleaner_4.112.exe
2015-03-11 15:05 - 2015-03-11 15:18 - 00000000 ____D () C:\ProgramData\ASGVIS
2015-03-11 15:05 - 2015-03-11 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chaos Group
2015-03-11 14:57 - 2015-01-12 07:39 - 00002139 _____ () C:\Users\Miroslav\Desktop\AutoCAD 2015.lnk
2015-03-11 14:51 - 2015-03-11 14:51 - 00003120 _____ () C:\windows\SysWOW64\ALLFSAF14a.ocx
2015-03-11 14:51 - 2015-03-11 14:51 - 00002040 _____ () C:\Users\Public\Desktop\SketchUp 2014.lnk
2015-03-11 14:51 - 2015-03-11 14:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2014
2015-03-11 14:33 - 2015-03-11 14:33 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-03-11 13:09 - 2015-03-11 13:23 - 00000000 ____D () C:\Program Files (x86)\Air Globe
2015-03-11 13:09 - 2015-03-11 13:09 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\QuickScan
2015-03-11 13:09 - 2015-03-11 13:09 - 00000000 ____D () C:\Program Files (x86)\b8d73ad6-1476-4f63-b012-bb37923f070e
2015-03-11 13:08 - 2015-03-11 15:45 - 00001720 _____ () C:\windows\Tasks\IHYDARN.job
2015-03-11 13:08 - 2015-03-11 13:20 - 00000000 ____D () C:\Program Files (x86)\CinemaP-1.8cV11.03
2015-03-11 13:08 - 2015-03-11 13:08 - 01958400 _____ (Cinema PlusV11.03) C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe
2015-03-11 13:08 - 2015-03-11 13:08 - 00004738 _____ () C:\windows\System32\Tasks\IHYDARN
2015-03-11 13:08 - 2015-03-11 13:08 - 00000000 ____D () C:\Program Files (x86)\76c74ff0-07f5-4709-90c9-c05f8fa9bdac
2015-03-10 12:43 - 2015-03-10 12:39 - 00001282 _____ () C:\Users\Miroslav\Desktop\Adobe Dreamweaver CC 2014.lnk
2015-03-10 12:40 - 2015-03-10 12:40 - 00003514 _____ () C:\windows\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-mirdos@outlook.cz
2015-03-10 12:39 - 2015-03-10 12:39 - 00001282 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC 2014.lnk
2015-03-10 12:28 - 2015-03-11 15:44 - 00007650 _____ () C:\windows\PFRO.log
2015-03-10 12:24 - 2015-03-10 17:24 - 00000000 ____D () C:\Users\Miroslav\Desktop\text
2015-03-10 10:47 - 2015-03-10 10:47 - 12518229 _____ () C:\Users\Miroslav\Downloads\Suntiware_13-2-DEMO.zip
2015-03-10 10:34 - 2015-03-10 12:04 - 00000000 ____D () C:\Program Files\Adobe
2015-03-10 10:31 - 2015-03-10 10:32 - 20613771 _____ () C:\Users\Miroslav\Downloads\suntiware_14-1.zip
2015-03-10 10:29 - 2015-03-10 10:29 - 00000000 ___RD () C:\Users\Miroslav\Creative Cloud Files
2015-03-10 10:13 - 2015-03-10 10:13 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\PDAppFlex
2015-03-10 10:02 - 2015-03-10 12:39 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-03-10 09:48 - 2015-03-10 09:48 - 00000000 ____D () C:\Users\Miroslav\DO~CUWG5
2015-03-09 22:30 - 2015-03-09 22:30 - 00005487 _____ () C:\Users\Miroslav\AppData\Roaming\IHYDARN
2015-03-09 10:07 - 2015-03-09 10:07 - 00002997 _____ () C:\Users\Miroslav\Desktop\XML Viewer.lnk
2015-03-09 10:05 - 2015-03-09 10:05 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Viewer
2015-03-09 10:05 - 2015-03-09 10:05 - 00000000 ____D () C:\Program Files (x86)\MindFusion Limited
2015-03-02 07:16 - 2015-03-02 07:16 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2015-02-20 08:52 - 2015-02-20 08:52 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\NetDirect
2015-02-16 07:13 - 2015-03-11 15:56 - 01679951 _____ () C:\windows\WindowsUpdate.log
2015-02-14 11:00 - 2015-02-27 09:34 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\PioneerLog
2015-02-14 10:59 - 2015-02-14 10:59 - 00000000 ____D () C:\Users\Miroslav\Documents\rekordbox
2015-02-14 10:59 - 2015-02-14 10:59 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Pioneer
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 16:36 - 2014-08-05 06:28 - 00000000 ____D () C:\Users\Miroslav\Documents\Soubory aplikace Outlook
2015-03-11 16:32 - 2014-08-04 09:07 - 00003994 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{3DB0DA44-4792-493B-82B8-028069F1D3CB}
2015-03-11 16:28 - 2014-08-04 09:08 - 00000984 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-11 16:02 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sru
2015-03-11 15:54 - 2014-08-04 09:04 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-931785541-2971233630-2540198836-1001
2015-03-11 15:49 - 2014-07-11 10:28 - 00724228 _____ () C:\windows\system32\perfh005.dat
2015-03-11 15:49 - 2014-07-11 10:28 - 00167054 _____ () C:\windows\system32\perfc005.dat
2015-03-11 15:49 - 2014-03-18 16:32 - 01748858 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-11 15:47 - 2014-08-04 09:08 - 00002482 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-11 15:45 - 2014-08-04 09:08 - 00000980 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-11 15:45 - 2014-08-04 09:01 - 00000000 __RDO () C:\Users\Miroslav\OneDrive
2015-03-11 15:44 - 2013-08-22 15:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-11 15:44 - 2013-08-22 14:25 - 00262144 ___SH () C:\windows\system32\config\BBI
2015-03-11 15:08 - 2014-11-28 11:32 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\uTorrent
2015-03-11 15:04 - 2014-11-28 12:12 - 00000000 ____D () C:\Users\Miroslav\Downloads\torrent
2015-03-11 14:53 - 2014-08-04 12:33 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\SketchUp
2015-03-11 14:51 - 2014-08-04 12:31 - 00000000 ____D () C:\ProgramData\SketchUp
2015-03-11 14:51 - 2014-08-04 12:31 - 00000000 ____D () C:\Program Files (x86)\SketchUp
2015-03-11 14:37 - 2014-09-25 10:42 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\vlc
2015-03-11 14:37 - 2014-08-05 08:12 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\Adobe
2015-03-11 14:35 - 2014-08-04 13:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-03-11 14:35 - 2014-08-04 08:59 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Adobe
2015-03-11 14:33 - 2014-08-04 13:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-03-11 13:35 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\AppReadiness
2015-03-11 13:20 - 2014-08-06 09:00 - 02481664 ___SH () C:\Users\Miroslav\Desktop\Thumbs.db
2015-03-11 13:20 - 2013-08-22 15:44 - 00497864 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-11 13:10 - 2014-08-04 08:59 - 00001641 _____ () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-11 13:10 - 2013-08-22 14:25 - 00000301 _____ () C:\windows\win.ini
2015-03-11 13:08 - 2014-08-04 11:55 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft
2015-03-11 13:01 - 2014-08-14 13:53 - 03885568 ___SH () C:\Users\Miroslav\Downloads\Thumbs.db
2015-03-10 17:27 - 2014-08-18 08:27 - 00000000 ___RD () C:\Users\Miroslav\Dropbox
2015-03-10 17:27 - 2014-08-04 08:59 - 00000000 ____D () C:\Users\Miroslav
2015-03-10 17:25 - 2014-08-18 08:26 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Dropbox
2015-03-06 13:55 - 2015-01-09 11:01 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\ViberPC
2015-03-06 13:55 - 2015-01-09 11:01 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\Viber
2015-03-03 14:17 - 2014-08-11 07:18 - 00295552 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-02-27 17:32 - 2014-08-04 12:50 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\XnView
2015-02-27 17:24 - 2014-09-03 06:55 - 00000000 ____D () C:\Users\Miroslav\Documents\Reg
2015-02-26 15:09 - 2014-08-04 12:19 - 00000000 ____D () C:\Users\Miroslav\Desktop\Údržba
2015-02-20 10:22 - 2015-01-19 07:45 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\netDirect
2015-02-14 10:24 - 2014-08-18 08:26 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-13 12:29 - 2014-08-04 09:08 - 00000000 ____D () C:\Program Files (x86)\Google
2015-02-09 07:23 - 2014-08-04 09:08 - 00003956 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-09 07:23 - 2014-08-04 09:08 - 00003720 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories =======
2014-02-18 05:12 - 2014-02-18 05:12 - 0121306 _____ () C:\Program Files\Acknowledgements.rtf
2014-10-15 05:42 - 2014-10-15 05:42 - 3022480 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_dsp.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0145040 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_link.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 1556112 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_manager.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0538768 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_musicid.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0273040 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_submit.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 2084648 _____ (Apple, Inc) C:\Program Files\iAdCore.dll
2014-02-18 05:07 - 2014-02-18 05:07 - 0112968 _____ (Apple Inc.) C:\Program Files\ITDetector.ocx
2014-10-15 05:42 - 2014-10-15 05:42 - 27444520 _____ (Apple Inc.) C:\Program Files\iTunes.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 4175144 _____ (Apple Inc.) C:\Program Files\iTunes.exe
2014-10-15 05:42 - 2014-10-15 05:42 - 0440104 _____ (Apple Inc.) C:\Program Files\iTunesAdmin.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0173352 _____ (Apple Inc.) C:\Program Files\iTunesHelper.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0157480 _____ (Apple Inc.) C:\Program Files\iTunesHelper.exe
2014-10-15 05:42 - 2014-10-15 05:42 - 0310568 _____ (Apple Inc.) C:\Program Files\iTunesOutlookAddIn.dll
2015-03-09 22:30 - 2015-03-09 22:30 - 0005487 _____ () C:\Users\Miroslav\AppData\Roaming\IHYDARN
2015-03-11 13:08 - 2015-03-11 13:08 - 1958400 _____ (Cinema PlusV11.03) C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe
2015-01-06 17:06 - 2015-01-06 17:06 - 0000017 _____ () C:\Users\Miroslav\AppData\Local\resmon.resmoncfg
2014-08-18 15:02 - 2014-08-18 15:02 - 0000445 _____ () C:\ProgramData\hpzinstall.log
Some content of TEMP:
====================
C:\Users\Miroslav\AppData\Local\Temp\8205.exe
C:\Users\Miroslav\AppData\Local\Temp\8414.exe
C:\Users\Miroslav\AppData\Local\Temp\8950.exe
C:\Users\Miroslav\AppData\Local\Temp\b_setup.exe
C:\Users\Miroslav\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdt4wio.dll
C:\Users\Miroslav\AppData\Local\Temp\Quarantine.exe
C:\Users\Miroslav\AppData\Local\Temp\sqlite3.dll
C:\Users\Miroslav\AppData\Local\Temp\vcredist_vs2005_x86.exe
C:\Users\Miroslav\AppData\Local\Temp\vcredist_vs2010_x64.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-04 07:30
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (Windows) (Fixed) (Total:226.35 GB) (Free:143.97 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:10.65 GB) (Free:1.36 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (DATADRIVE) (Fixed) (Total:2794.39 GB) (Free:2656.16 GB) NTFS
Available physical RAM: 14386.18 MB
Total physical RAM: 16337.06 MB
Percentage of memory in use: 11%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 238.5 GB) (Disk ID: 14418506)
Disk: 1 (Size: 2794.5 GB) (Disk ID: 73CFCDB3)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\DriverNavigator Scheduled Scan.job => C:\Program Files\Easeware\DriverNavigator\DriverNavigator.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\IHYDARN.job => C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\Users\Miroslav\OneDrive:ms-properties
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Miroslav\Desktop" je 80 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Díky za odpověď.
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Miroslav (administrator) on PC-KANCELAR on 11-03-2015 16:40:21
Running from C:\Users\Miroslav\Desktop
Loaded Profiles: Miroslav (Available profiles: Miroslav)
Platform: Windows 8.1 (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\Beats64.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
() C:\Program Files (x86)\Razer\Lachesis\razerhid.exe
(razercfg MFC Application) C:\Program Files (x86)\Razer\Lachesis\OSD.exe
() C:\Program Files (x86)\Razer\Lachesis\razertra.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Lachesis\razerofa.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Ghisler Software GmbH) C:\Program Files\TotalCMD\TOTALCMD64.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Miroslav\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2014-01-07] (Hewlett-Packard )
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2014-01-07] (IDT, Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2015-02-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-01-24] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISUSScheduler] => C:\Program Files (x86)\Common Files\InstallShield\UpdateService\issch.exe [81920 2004-06-14] (InstallShield Software Corporation)
HKLM-x32\...\Run: [Lachesis] => C:\Program Files (x86)\Razer\Lachesis\razerhid.exe [248320 2009-11-10] ()
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [926896 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [ISUSPM Startup] => c:\Program Files (x86)\Common Files\InstallShield\UpdateService\ISUSPM.exe [221184 2004-06-14] (InstallShield Software Corporation)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Run: [GoogleChromeAutoLaunch_32355425123F7F9C052AB58FA7004C44] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [809288 2015-03-07] (Google Inc.)
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\Policies\Explorer: []
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\...\MountPoints2: {bcdf6e9e-43ae-11e4-8267-a0d3c13f7eff} - "G:\HTC_Sync_Manager_PC.exe"
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll No File
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Miroslav\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll (Autodesk, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
HKU\S-1-5-21-931785541-2971233630-2540198836-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.omniboxes.com/?type=hp&ts=14 ... 1794401479
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKLM -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = http://www.omniboxes.com/web/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {707BC4A0-FB7A-4131-9DA5-14E54F088308} URL = http://www.amazon.co.uk/s/ref=azs_osd_i ... earchTerms}
SearchScopes: HKU\S-1-5-21-931785541-2971233630-2540198836-1001 -> {EE804AE7-BB17-460D-8D8D-EB05F6A35E55} URL = https://search.yahoo.com/search?fr=chr- ... earchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2011-02-11] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-30] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-12-21] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-30] (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{D8B99B1A-27EA-46D5-877A-68647B777EB8}: [NameServer] 10.0.0.138
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe http://www.omniboxes.com/?type=sc&ts=14 ... 1794401479
FireFox:
========
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll No File
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-08-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-08-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-09] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-09] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2012-09-23] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll No File
Chrome:
=======
CHR HomePage: Profile 1 -> https://www.google.cz/
CHR StartupUrls: Profile 1 -> "hxxp://google.cz/"
CHR DefaultSuggestURL: Profile 1 -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Translate) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-01-05]
CHR Extension: (Google Drive) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-05]
CHR Extension: (YouTube) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-05]
CHR Extension: (Google Search) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-05]
CHR Extension: (Google Sheets) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-05]
CHR Extension: (Page Analytics (by Google)) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fnbdnhhicmebfgdgglcdacdapkcihcoh [2015-01-20]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-01-05]
CHR Extension: (AdBlock) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-05]
CHR Extension: (TweetDeck by Twitter) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\hbdpomandigafcibbmofojjchbcdagbl [2015-01-05]
CHR Extension: (Dropbox) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2015-01-05]
CHR Extension: (Type Sample) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\jobccjjaffckfoggljonehppmldgmkmh [2015-02-27]
CHR Extension: (Wordpress Admin Bar Control) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\joldejophkhmeajgjenfnfdpfjkalckn [2015-01-20]
CHR Extension: (Převod měn) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\kjehaadplpgckpgeoddpnijogjaldela [2015-01-05]
CHR Extension: (Google Maps) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-01-05]
CHR Extension: (Google Mail Checker) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-01-05]
CHR Extension: (Hangouts) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-01-05]
CHR Extension: (Save to Pocket) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2015-01-06]
CHR Extension: (Google Wallet) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-05]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2015-03-02]
CHR Extension: (Gmail) - C:\Users\Miroslav\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc.)
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\41.0.2272.41\remoting_host.exe [56648 2015-02-01] (Google Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-12] (Intel Corporation)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [340480 2014-01-07] (IDT, Inc.) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
S2 Update Air Globe; "C:\Program Files (x86)\Air Globe\updateAirGlobe.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2014-03-11] (Advanced Micro Devices)
U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [293888 2014-11-28] (Alcohol Soft Development Team)
S3 lachesis35g; C:\Windows\System32\drivers\lachesis35g.sys [11776 2012-12-10] (Razer USA Ltd) [File not signed]
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverx64.sys [99288 2013-08-12] (Intel Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [386680 2014-08-04] (Duplex Secure Ltd.)
R3 VaneFltr; C:\Windows\system32\drivers\Lachesis.sys [29952 2009-10-16] (Razer (Asia-Pacific) Pte Ltd)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
U3 McAPExe; No ImagePath
U3 McMPFSvc; No ImagePath
U3 McNaiAnn; No ImagePath
U3 mcpltsvc; No ImagePath
U3 mfecore; No ImagePath
U3 MSK80Service; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 16:40 - 2015-03-11 16:40 - 00023235 _____ () C:\Users\Miroslav\Desktop\FRST.txt
2015-03-11 16:39 - 2015-03-11 16:40 - 00000000 ____D () C:\FRST
2015-03-11 16:37 - 2015-03-11 16:37 - 00112640 _____ (forum.viry.cz) C:\Users\Miroslav\Desktop\FRSTLauncher.exe
2015-03-11 16:35 - 2015-03-11 16:35 - 02095616 _____ (Farbar) C:\Users\Miroslav\Desktop\FRST64.exe
2015-03-11 16:29 - 2015-03-11 16:29 - 00388608 _____ (Trend Micro Inc.) C:\Users\Miroslav\Downloads\hijackthis.exe
2015-03-11 16:29 - 2015-03-11 16:29 - 00010296 _____ () C:\Users\Miroslav\Downloads\hijackthis.log
2015-03-11 16:21 - 2015-03-11 16:21 - 01720017 _____ () C:\Users\Miroslav\Desktop\Romotop_KV662.skp
2015-03-11 16:10 - 2015-03-11 16:10 - 01272937 _____ () C:\Users\Miroslav\Downloads\kv662.skp
2015-03-11 16:10 - 2015-03-11 16:10 - 01083835 _____ () C:\Users\Miroslav\Desktop\prislusenstvi.rar
2015-03-11 15:42 - 2015-03-11 15:44 - 00000000 ____D () C:\AdwCleaner
2015-03-11 15:31 - 2015-03-11 15:32 - 00000000 ____D () C:\Users\Miroslav\Desktop\kv
2015-03-11 15:31 - 2015-03-11 15:31 - 00000788 _____ () C:\windows\setupact.log
2015-03-11 15:31 - 2015-03-11 15:31 - 00000000 _____ () C:\windows\setuperr.log
2015-03-11 15:24 - 2015-03-11 15:25 - 02171392 _____ () C:\Users\Miroslav\Desktop\adwcleaner_4.112.exe
2015-03-11 15:05 - 2015-03-11 15:18 - 00000000 ____D () C:\ProgramData\ASGVIS
2015-03-11 15:05 - 2015-03-11 15:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chaos Group
2015-03-11 14:57 - 2015-01-12 07:39 - 00002139 _____ () C:\Users\Miroslav\Desktop\AutoCAD 2015.lnk
2015-03-11 14:51 - 2015-03-11 14:51 - 00003120 _____ () C:\windows\SysWOW64\ALLFSAF14a.ocx
2015-03-11 14:51 - 2015-03-11 14:51 - 00002040 _____ () C:\Users\Public\Desktop\SketchUp 2014.lnk
2015-03-11 14:51 - 2015-03-11 14:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2014
2015-03-11 14:33 - 2015-03-11 14:33 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-03-11 13:09 - 2015-03-11 13:23 - 00000000 ____D () C:\Program Files (x86)\Air Globe
2015-03-11 13:09 - 2015-03-11 13:09 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\QuickScan
2015-03-11 13:09 - 2015-03-11 13:09 - 00000000 ____D () C:\Program Files (x86)\b8d73ad6-1476-4f63-b012-bb37923f070e
2015-03-11 13:08 - 2015-03-11 15:45 - 00001720 _____ () C:\windows\Tasks\IHYDARN.job
2015-03-11 13:08 - 2015-03-11 13:20 - 00000000 ____D () C:\Program Files (x86)\CinemaP-1.8cV11.03
2015-03-11 13:08 - 2015-03-11 13:08 - 01958400 _____ (Cinema PlusV11.03) C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe
2015-03-11 13:08 - 2015-03-11 13:08 - 00004738 _____ () C:\windows\System32\Tasks\IHYDARN
2015-03-11 13:08 - 2015-03-11 13:08 - 00000000 ____D () C:\Program Files (x86)\76c74ff0-07f5-4709-90c9-c05f8fa9bdac
2015-03-10 12:43 - 2015-03-10 12:39 - 00001282 _____ () C:\Users\Miroslav\Desktop\Adobe Dreamweaver CC 2014.lnk
2015-03-10 12:40 - 2015-03-10 12:40 - 00003514 _____ () C:\windows\System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-mirdos@outlook.cz
2015-03-10 12:39 - 2015-03-10 12:39 - 00001282 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Dreamweaver CC 2014.lnk
2015-03-10 12:28 - 2015-03-11 15:44 - 00007650 _____ () C:\windows\PFRO.log
2015-03-10 12:24 - 2015-03-10 17:24 - 00000000 ____D () C:\Users\Miroslav\Desktop\text
2015-03-10 10:47 - 2015-03-10 10:47 - 12518229 _____ () C:\Users\Miroslav\Downloads\Suntiware_13-2-DEMO.zip
2015-03-10 10:34 - 2015-03-10 12:04 - 00000000 ____D () C:\Program Files\Adobe
2015-03-10 10:31 - 2015-03-10 10:32 - 20613771 _____ () C:\Users\Miroslav\Downloads\suntiware_14-1.zip
2015-03-10 10:29 - 2015-03-10 10:29 - 00000000 ___RD () C:\Users\Miroslav\Creative Cloud Files
2015-03-10 10:13 - 2015-03-10 10:13 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\PDAppFlex
2015-03-10 10:02 - 2015-03-10 12:39 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-03-10 09:48 - 2015-03-10 09:48 - 00000000 ____D () C:\Users\Miroslav\DO~CUWG5
2015-03-09 22:30 - 2015-03-09 22:30 - 00005487 _____ () C:\Users\Miroslav\AppData\Roaming\IHYDARN
2015-03-09 10:07 - 2015-03-09 10:07 - 00002997 _____ () C:\Users\Miroslav\Desktop\XML Viewer.lnk
2015-03-09 10:05 - 2015-03-09 10:05 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XML Viewer
2015-03-09 10:05 - 2015-03-09 10:05 - 00000000 ____D () C:\Program Files (x86)\MindFusion Limited
2015-03-02 07:16 - 2015-03-02 07:16 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2015-02-20 08:52 - 2015-02-20 08:52 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\NetDirect
2015-02-16 07:13 - 2015-03-11 15:56 - 01679951 _____ () C:\windows\WindowsUpdate.log
2015-02-14 11:00 - 2015-02-27 09:34 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\PioneerLog
2015-02-14 10:59 - 2015-02-14 10:59 - 00000000 ____D () C:\Users\Miroslav\Documents\rekordbox
2015-02-14 10:59 - 2015-02-14 10:59 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Pioneer
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-11 16:36 - 2014-08-05 06:28 - 00000000 ____D () C:\Users\Miroslav\Documents\Soubory aplikace Outlook
2015-03-11 16:32 - 2014-08-04 09:07 - 00003994 _____ () C:\windows\System32\Tasks\User_Feed_Synchronization-{3DB0DA44-4792-493B-82B8-028069F1D3CB}
2015-03-11 16:28 - 2014-08-04 09:08 - 00000984 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-11 16:02 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\system32\sru
2015-03-11 15:54 - 2014-08-04 09:04 - 00003598 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-931785541-2971233630-2540198836-1001
2015-03-11 15:49 - 2014-07-11 10:28 - 00724228 _____ () C:\windows\system32\perfh005.dat
2015-03-11 15:49 - 2014-07-11 10:28 - 00167054 _____ () C:\windows\system32\perfc005.dat
2015-03-11 15:49 - 2014-03-18 16:32 - 01748858 _____ () C:\windows\system32\PerfStringBackup.INI
2015-03-11 15:47 - 2014-08-04 09:08 - 00002482 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-11 15:45 - 2014-08-04 09:08 - 00000980 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-11 15:45 - 2014-08-04 09:01 - 00000000 __RDO () C:\Users\Miroslav\OneDrive
2015-03-11 15:44 - 2013-08-22 15:45 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-03-11 15:44 - 2013-08-22 14:25 - 00262144 ___SH () C:\windows\system32\config\BBI
2015-03-11 15:08 - 2014-11-28 11:32 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\uTorrent
2015-03-11 15:04 - 2014-11-28 12:12 - 00000000 ____D () C:\Users\Miroslav\Downloads\torrent
2015-03-11 14:53 - 2014-08-04 12:33 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\SketchUp
2015-03-11 14:51 - 2014-08-04 12:31 - 00000000 ____D () C:\ProgramData\SketchUp
2015-03-11 14:51 - 2014-08-04 12:31 - 00000000 ____D () C:\Program Files (x86)\SketchUp
2015-03-11 14:37 - 2014-09-25 10:42 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\vlc
2015-03-11 14:37 - 2014-08-05 08:12 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\Adobe
2015-03-11 14:35 - 2014-08-04 13:56 - 00000000 ____D () C:\ProgramData\Adobe
2015-03-11 14:35 - 2014-08-04 08:59 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Adobe
2015-03-11 14:33 - 2014-08-04 13:56 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-03-11 13:35 - 2013-08-22 16:36 - 00000000 ____D () C:\windows\AppReadiness
2015-03-11 13:20 - 2014-08-06 09:00 - 02481664 ___SH () C:\Users\Miroslav\Desktop\Thumbs.db
2015-03-11 13:20 - 2013-08-22 15:44 - 00497864 _____ () C:\windows\system32\FNTCACHE.DAT
2015-03-11 13:10 - 2014-08-04 08:59 - 00001641 _____ () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-03-11 13:10 - 2013-08-22 14:25 - 00000301 _____ () C:\windows\win.ini
2015-03-11 13:08 - 2014-08-04 11:55 - 00000000 ____D () C:\Program Files (x86)\Alcohol Soft
2015-03-11 13:01 - 2014-08-14 13:53 - 03885568 ___SH () C:\Users\Miroslav\Downloads\Thumbs.db
2015-03-10 17:27 - 2014-08-18 08:27 - 00000000 ___RD () C:\Users\Miroslav\Dropbox
2015-03-10 17:27 - 2014-08-04 08:59 - 00000000 ____D () C:\Users\Miroslav
2015-03-10 17:25 - 2014-08-18 08:26 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Dropbox
2015-03-06 13:55 - 2015-01-09 11:01 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\ViberPC
2015-03-06 13:55 - 2015-01-09 11:01 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\Viber
2015-03-03 14:17 - 2014-08-11 07:18 - 00295552 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2015-02-27 17:32 - 2014-08-04 12:50 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\XnView
2015-02-27 17:24 - 2014-09-03 06:55 - 00000000 ____D () C:\Users\Miroslav\Documents\Reg
2015-02-26 15:09 - 2014-08-04 12:19 - 00000000 ____D () C:\Users\Miroslav\Desktop\Údržba
2015-02-20 10:22 - 2015-01-19 07:45 - 00000000 ____D () C:\Users\Miroslav\AppData\Local\netDirect
2015-02-14 10:24 - 2014-08-18 08:26 - 00000000 ____D () C:\Users\Miroslav\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-02-13 12:29 - 2014-08-04 09:08 - 00000000 ____D () C:\Program Files (x86)\Google
2015-02-09 07:23 - 2014-08-04 09:08 - 00003956 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-09 07:23 - 2014-08-04 09:08 - 00003720 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
==================== Files in the root of some directories =======
2014-02-18 05:12 - 2014-02-18 05:12 - 0121306 _____ () C:\Program Files\Acknowledgements.rtf
2014-10-15 05:42 - 2014-10-15 05:42 - 3022480 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_dsp.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0145040 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_link.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 1556112 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_manager.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0538768 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_musicid.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0273040 _____ (Gracenote, Inc.) C:\Program Files\gnsdk_submit.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 2084648 _____ (Apple, Inc) C:\Program Files\iAdCore.dll
2014-02-18 05:07 - 2014-02-18 05:07 - 0112968 _____ (Apple Inc.) C:\Program Files\ITDetector.ocx
2014-10-15 05:42 - 2014-10-15 05:42 - 27444520 _____ (Apple Inc.) C:\Program Files\iTunes.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 4175144 _____ (Apple Inc.) C:\Program Files\iTunes.exe
2014-10-15 05:42 - 2014-10-15 05:42 - 0440104 _____ (Apple Inc.) C:\Program Files\iTunesAdmin.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0173352 _____ (Apple Inc.) C:\Program Files\iTunesHelper.dll
2014-10-15 05:42 - 2014-10-15 05:42 - 0157480 _____ (Apple Inc.) C:\Program Files\iTunesHelper.exe
2014-10-15 05:42 - 2014-10-15 05:42 - 0310568 _____ (Apple Inc.) C:\Program Files\iTunesOutlookAddIn.dll
2015-03-09 22:30 - 2015-03-09 22:30 - 0005487 _____ () C:\Users\Miroslav\AppData\Roaming\IHYDARN
2015-03-11 13:08 - 2015-03-11 13:08 - 1958400 _____ (Cinema PlusV11.03) C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe
2015-01-06 17:06 - 2015-01-06 17:06 - 0000017 _____ () C:\Users\Miroslav\AppData\Local\resmon.resmoncfg
2014-08-18 15:02 - 2014-08-18 15:02 - 0000445 _____ () C:\ProgramData\hpzinstall.log
Some content of TEMP:
====================
C:\Users\Miroslav\AppData\Local\Temp\8205.exe
C:\Users\Miroslav\AppData\Local\Temp\8414.exe
C:\Users\Miroslav\AppData\Local\Temp\8950.exe
C:\Users\Miroslav\AppData\Local\Temp\b_setup.exe
C:\Users\Miroslav\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdt4wio.dll
C:\Users\Miroslav\AppData\Local\Temp\Quarantine.exe
C:\Users\Miroslav\AppData\Local\Temp\sqlite3.dll
C:\Users\Miroslav\AppData\Local\Temp\vcredist_vs2005_x86.exe
C:\Users\Miroslav\AppData\Local\Temp\vcredist_vs2010_x64.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-04 07:30
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (Windows) (Fixed) (Total:226.35 GB) (Free:143.97 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (Recovery Image) (Fixed) (Total:10.65 GB) (Free:1.36 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (DATADRIVE) (Fixed) (Total:2794.39 GB) (Free:2656.16 GB) NTFS
Available physical RAM: 14386.18 MB
Total physical RAM: 16337.06 MB
Percentage of memory in use: 11%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 238.5 GB) (Disk ID: 14418506)
Disk: 1 (Size: 2794.5 GB) (Disk ID: 73CFCDB3)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\windows\Tasks\DriverNavigator Scheduled Scan.job => C:\Program Files\Easeware\DriverNavigator\DriverNavigator.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\IHYDARN.job => C:\Users\Miroslav\AppData\Roaming\IHYDARN.exe <==== ATTENTION
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\Temp:054203E4
AlternateDataStreams: C:\Users\Miroslav\OneDrive:ms-properties
==================== Security Center ==================
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Miroslav\Desktop" je 80 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================