Stránka 1 z 1

Prosím pommoc, počítač napadený, RSIT log

Napsal: 05 črc 2015 08:59
od Taras
Zdravím vás, pokorně žádám o pomoc, počítač o který se jedná je zpomalený a zaplácaný malwarem.

zde je log z RSIT kdyby se na to měl někdo čas mrknou, děkuji ;)

Logfile of random's system information tool 1.10 (written by random/random)
Run by okadmin at 2015-07-05 09:43:47
Microsoft Windows 7 Home Premium
System drive C: has 37 GB (13%) free of 288 GB
Total RAM: 3003 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:43:54, on 5.7.2015
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\trend micro\okadmin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.seznam.cz/?clid=22668
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.seznam.cz/?sourceid=quick ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocník pro přihlášení ke službě Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {46897C77-E7A6-4c33-BFFB-E9C2E2718942} - (no file)
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKCU\..\Run: [HPAdvisorDock] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Optimizer Pro] C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\okadmin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Přidat na blog - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Přidat na blog Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GRA32A~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Easybits Services for Windows (ezSharedSvc) - EasyBits Software AS - C:\Windows\System32\ezSharedSvcHost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Unknown owner - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: RtVOsdService Installer (RtVOsdService) - Realtek Semiconductor Corp. - C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10330 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe"
"C:\Program Files\AVAST Software\Avast\avastui.exe" /nogui
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe"
"C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F2400 series#1410940670" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" mode=windowless
"C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe"
"C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe"
"C:\Program Files\Realtek\RtVOsd\RtVOsd.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4152.0.1162135119\783358047" --supports-dual-gpus=false --gpu-driver-bug-workarounds=0,3,12,22 --disable-accelerated-video-decode --gpu-vendor-id=0x8086 --gpu-device-id=0x2a42 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=8.15.10.2086 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.2.963976397\1978663669" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --extension-process --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.3.1478099803\1751442426" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.7.377504970\1720676437" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.8.771804529\971579929" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.15.180796406\745439105" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.23.1154358226\1579222950" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.26.1489230119\862097381" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=cs --force-fieldtrials=BrowserPreReadExperiment/100-pct-default/Prefetch/ContentPrefetchPrefetchOn/Prerender/PrerenderMulti/PrerenderFromOmnibox/OmniboxPrerenderEnabled/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Session-Randomized-Uniformity-Trial-5-Percent/default/UMA-Uniformity-Trial-1-Percent/group_74/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/default/UMA-Uniformity-Trial-5-Percent/group_06/UMA-Uniformity-Trial-50-Percent/group_01/ --enable-threaded-compositing --renderer-print-preview --disable-html-notifications --extensions-on-chrome-urls --disable-accelerated-2d-canvas --disable-accelerated-video-decode --channel="4152.28.946185569\378415056" /prefetch:673131151
"C:\Users\okadmin\Downloads\RSITx64.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"

taskeng.exe {E9801E89-3635-4FD7-AB43-B978812D0E15}

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\HPCeeScheduleForokadmin.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForokadmin (null)

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-16 705448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-15 43520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-16 586968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pro přihlášení ke službě Windows Live - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-08-15 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21 509496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{46897C77-E7A6-4c33-BFFB-E9C2E2718942}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-03-05 166424]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2010-04-23 2097960]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2010-05-26 6245408]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"HPAdvisorDock"=C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [2010-02-09 1712184]
"LightScribe Control Panel"=C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2011-03-04 2741616]
"Optimizer Pro"=C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [2013-10-28 134648]
"uTorrent"=C:\Users\okadmin\AppData\Roaming\uTorrent\uTorrent.exe [2015-07-02 1693024]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2011-01-20 1305408]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-06-01 8358680]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2015-06-29 53288576]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HP Quick Launch"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [2010-07-02 602680]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"mobilegeni daemon"=C:\Program Files (x86)\Mobogenie\DaemonProcess.exe [2013-10-30 746176]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2015-03-30 5227648]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="c:\progra~2\search~1\search~1\bin\spvc64~1.dll c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2010-03-05 269824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E54729E8-BB3D-4270-9D49-7389EA579090}"=C:\Windows\SysWow64\EZUPBH~1.DLL [2010-08-14 52920]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2006-10-27 2210608]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableLockWorkstation"=0
"DisableTaskMgr"=0
"DisableChangePassword"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"HideFastUserSwitching"=0
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"EnableShellExecuteHooks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-07-05 09:43:47 ----D---- C:\rsit
2015-07-05 09:43:47 ----D---- C:\Program Files\trend micro
2015-07-04 21:35:51 ----RD---- C:\Program Files (x86)\Skype
2015-07-04 10:55:07 ----D---- C:\Program Files\CCleaner
2015-07-01 16:32:16 ----D---- C:\Users\okadmin\AppData\Roaming\Skype
2015-07-01 16:32:01 ----D---- C:\ProgramData\Skype
2015-06-25 08:32:28 ----D---- C:\ProgramData\GRETECH

======List of files/folders modified in the last 1 month======

2015-07-05 09:43:52 ----D---- C:\Windows\Temp
2015-07-05 09:43:47 ----D---- C:\Program Files
2015-07-05 01:06:23 ----D---- C:\Windows\inf
2015-07-04 21:42:29 ----SHD---- C:\Windows\Installer
2015-07-04 21:42:16 ----HD---- C:\Config.Msi
2015-07-04 21:36:24 ----D---- C:\Program Files (x86)\Common Files
2015-07-04 21:35:51 ----D---- C:\Program Files (x86)
2015-07-04 21:35:50 ----D---- C:\Windows\SysWOW64
2015-07-04 21:16:52 ----D---- C:\Windows\system32\Tasks
2015-07-04 21:14:31 ----SHD---- C:\System Volume Information
2015-07-04 20:51:59 ----A---- C:\Windows\win.ini
2015-07-04 20:50:53 ----D---- C:\Windows\System32
2015-07-04 20:50:43 ----D---- C:\Windows\system32\catroot2
2015-07-04 20:49:44 ----D---- C:\Windows\system32\config
2015-07-04 20:46:28 ----D---- C:\ProgramData\LightScribe
2015-07-04 20:45:29 ----D---- C:\Users\okadmin\AppData\Roaming\uTorrent
2015-07-04 14:14:14 ----D---- C:\Windows
2015-07-04 12:08:33 ----HD---- C:\ProgramData
2015-07-04 10:57:54 ----D---- C:\Users\okadmin\AppData\Roaming\DAEMON Tools Lite
2015-07-01 08:57:12 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-06-25 09:04:37 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2014-12-16 65776]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2014-12-16 267632]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2010-04-13 540696]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 214096]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2011-06-06 513080]
R1 {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}Gw64;{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}Gw64; C:\Windows\system32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}Gw64.sys [2014-04-24 61120]
R1 {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}w64;{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}w64; C:\Windows\system32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}w64.sys [2014-06-09 61120]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2014-12-16 93568]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2014-12-16 1050432]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2014-12-16 436624]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2014-12-16 29208]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2014-12-16 83280]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2014-12-16 116728]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2009-07-14 79360]
R3 huawei_enumerator;huawei_enumerator; C:\Windows\system32\DRIVERS\ew_jubusenum.sys [2011-01-30 86016]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-03-05 10300800]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2010-05-26 2374560]
R3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys [2009-09-29 16384]
R3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys [2009-09-29 14848]
R3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys [2009-09-29 17408]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver; C:\Windows\system32\DRIVERS\netr28x.sys [2010-06-23 931168]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2010-03-23 347680]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2010-04-23 318000]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S2 atksgt;atksgt; C:\Windows\system32\DRIVERS\atksgt.sys [2011-07-07 303616]
S2 lirsgt;lirsgt; C:\Windows\system32\DRIVERS\lirsgt.sys [2011-07-07 35328]
S3 ac6yvi9b;ac6yvi9b; C:\Windows\system32\drivers\ac6yvi9b.sys []
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2009-07-14 551936]
S3 BTMCOM;Bluetooth Serial Port; C:\Windows\System32\Drivers\btmcom.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2009-07-14 19968]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device; C:\Windows\system32\DRIVERS\ew_hwusbdev.sys [2010-07-27 117248]
S3 Huawei;HUAWEI Mobile Connect - USB Smart Card Reader; C:\Windows\system32\DRIVERS\ewdcsc.sys []
S3 huawei_cdcacm;huawei_cdcacm; C:\Windows\system32\DRIVERS\ew_jucdcacm.sys [2011-02-25 98816]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys []
S3 hwusbdev;Huawei DataCard USB PNP Device; C:\Windows\system32\DRIVERS\ewusbdev.sys []
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-06-10 5434368]
S3 PcaSp60;Rawether NDIS 6.X SPR Protocol Driver; C:\Windows\system32\DRIVERS\PcaSp60.sys [2010-05-19 38912]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12352]
S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-07-14 109056]
S3 SrvHsfHDA;SrvHsfHDA; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [2009-06-10 292864]
S3 SrvHsfV92;SrvHsfV92; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [2009-06-10 1485312]
S3 SrvHsfWinac;SrvHsfWinac; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [2009-06-10 740864]
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgx64bus.sys [2008-11-19 17920]
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgx64diag.sys [2008-11-19 27136]
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgx64modem.sys [2008-11-19 33792]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2009-07-14 41984]
S3 WDC_SAM;WD SCSI Pass Thru driver; C:\Windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2009-07-14 40448]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2009-11-18 98208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-12-16 50344]
R2 ezSharedSvc;Easybits Services for Windows; C:\Windows\syswow64\ezSharedSvcHost.exe [2010-04-23 514232]
R2 HP Wireless Assistant Service;HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [2010-06-18 103992]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-07-02 27192]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-03-04 73728]
R2 RtVOsdService;RtVOsdService Installer; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [2010-04-19 315392]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2011-03-28 799800]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-06-03 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-25 268976]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 05 črc 2015 09:03
od vyosek
Zdravim :)

:arrow: Stahnete AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
  • Ulozte nejlepe na plochu
  • Ukoncete vsechny programy
  • Po spusteni probehne stazeni databaze
  • Kliknete na Scan a nasledne Clean
  • Probehne oprava, restart PC a pak se objevi log, pripadne bude ulozen ve slozce c:\AdwCleaner\AdwCleaner[S?].txt, ten sem vlozte

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 05 črc 2015 09:56
od Taras
Díky za pomoc udělal sem vše jak bylo napsáno, zde je log:

# AdwCleaner v4.207 - Log vytvořen 05/07/2015 v 10:43:51
# Aktualizováno 21/06/2015 by Xplode
# Databáze : 2015-07-02.1 [Server]
# Operační system : Windows 7 Home Premium (x64)
# Uživatelské jméno : okadmin - OKADMIN-HP
# Spuštěno z : C:\Users\okadmin\Desktop\adwcleaner_4.207.exe
# Nastavení : Čištění

***** [ Služby ] *****

Služba Smazáno : {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}Gw64
Služba Smazáno : {c83c7c03-36f9-4f8f-aa6d-c837575d4eca}w64

***** [ Soubory / Složky ] *****

[!] Složka Smazáno : C:\ProgramData\apn
[!] Složka Smazáno : C:\ProgramData\Babylon
[!] Složka Smazáno : C:\ProgramData\BitGuard
[!] Složka Smazáno : C:\ProgramData\SaveItCoupons
[!] Složka Smazáno : C:\ProgramData\GoSave
[!] Složka Smazáno : C:\ProgramData\50COupons
[!] Složka Smazáno : C:\ProgramData\EnjoyCOOUpoon
[!] Složka Smazáno : C:\ProgramData\GoSavE
[!] Složka Smazáno : C:\ProgramData\grEatsavuing
[!] Složka Smazáno : C:\ProgramData\JonniCooUpon
[!] Složka Smazáno : C:\ProgramData\sAve Net
[!] Složka Smazáno : C:\ProgramData\YoutubeAdblocker
[!] Složka Smazáno : C:\ProgramData\50COupons
[!] Složka Smazáno : C:\ProgramData\ALlSSaver
[!] Složka Smazáno : C:\ProgramData\EnjoyCOOUpoon
[!] Složka Smazáno : C:\ProgramData\EnJoyCoupoon
[!] Složka Smazáno : C:\ProgramData\ExstrACouPon
[!] Složka Smazáno : C:\ProgramData\FFunDeaLs
[!] Složka Smazáno : C:\ProgramData\GoSavE
[!] Složka Smazáno : C:\ProgramData\grEatsavuing
[!] Složka Smazáno : C:\ProgramData\JonniCooUpon
[!] Složka Smazáno : C:\ProgramData\QueenCCoupoon
[!] Složka Smazáno : C:\ProgramData\RegularDeaLs
[!] Složka Smazáno : C:\ProgramData\saavIngtoyoU
[!] Složka Smazáno : C:\ProgramData\sAve Net
[!] Složka Smazáno : C:\ProgramData\SaveItCoupons
[!] Složka Smazáno : C:\ProgramData\ShowAppIt
[!] Složka Smazáno : C:\ProgramData\surfkeePait
[!] Složka Smazáno : C:\ProgramData\YoutubeAdblocker
[!] Složka Smazáno : C:\ProgramData\4e3452ab47b6fb8d
[!] Složka Smazáno : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EZDownloader
[!] Složka Smazáno : C:\Program Files (x86)\AskTBar
[!] Složka Smazáno : C:\Program Files (x86)\Conduit
[!] Složka Smazáno : C:\Program Files (x86)\EZDownloader
[!] Složka Smazáno : C:\Program Files (x86)\Mobogenie
[!] Složka Smazáno : C:\Program Files (x86)\Mp3Tube Toolbar
[!] Složka Smazáno : C:\Program Files (x86)\SearchProtect
[!] Složka Smazáno : C:\Program Files (x86)\SecretSauce
[!] Složka Smazáno : C:\Program Files (x86)\sw-booster
[!] Složka Smazáno : C:\Program Files (x86)\TornTV.com
[!] Složka Smazáno : C:\Program Files (x86)\GoSave
[!] Složka Smazáno : C:\Program Files (x86)\50COupons
[!] Složka Smazáno : C:\Program Files (x86)\EnjoyCOOUpoon
[!] Složka Smazáno : C:\Program Files (x86)\GoSavE
[!] Složka Smazáno : C:\Program Files (x86)\grEatsavuing
[!] Složka Smazáno : C:\Program Files (x86)\JonniCooUpon
[!] Složka Smazáno : C:\Program Files (x86)\sAve Net
[!] Složka Smazáno : C:\Program Files (x86)\YoutubeAdblocker
[!] Složka Smazáno : C:\Program Files (x86)\50COupons
[!] Složka Smazáno : C:\Program Files (x86)\EnjoyCOOUpoon
[!] Složka Smazáno : C:\Program Files (x86)\GoSavE
[!] Složka Smazáno : C:\Program Files (x86)\grEatsavuing
[!] Složka Smazáno : C:\Program Files (x86)\JonniCooUpon
[!] Složka Smazáno : C:\Program Files (x86)\sAve Net
[!] Složka Smazáno : C:\Program Files (x86)\YoutubeAdblocker
[!] Složka Smazáno : C:\Program Files (x86)\Optimizer Pro
[!] Složka Smazáno : C:\Windows\SysWOW64\BitGuard
[!] Složka Smazáno : C:\Windows\SysWOW64\dfrg
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Chromatic Browser
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\torch
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Chromatic Browser
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\torch
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Chromatic Browser
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\torch
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Chromatic Browser
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Conduit
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Mobogenie
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\onlysearch
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\RavenBleuSA
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\SearchProtect
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\torch
[!] Složka Smazáno : C:\Users\okadmin\AppData\LocalLow\Conduit
[!] Složka Smazáno : C:\Users\okadmin\AppData\LocalLow\HPAppData
[!] Složka Smazáno : C:\Users\okadmin\AppData\LocalLow\Mp3Tube Toolbar
[!] Složka Smazáno : C:\Users\okadmin\AppData\LocalLow\PriceGong
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\BabSolution
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\Babylon
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\EZDownloader
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\file scout
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\goforfiles
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\Optimizer Pro
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mobogenie
[!] Složka Smazáno : C:\Users\wangjihua\AppData\Local\Mobogenie
[!] Složka Smazáno : C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\0\Extensions\torntv@torntv.com.xpi
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjknneibmifpnmlkgfmcjhbajkehpbeb
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gamlmgkgpkoacendnhjdlccbijpkflbf
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdkpgbhhfnpjiembbpifcpfalfnflmop
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hibkhcnpkakjniplpfblaoikiggkopka
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibpbofogepkkeoockhkfcgngjkimndlp
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\ProgramData\klpghljanbclanopclomjifjbfkgdfan
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpghljanbclanopclomjifjbfkgdfan
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nidiblpdmncdebogndoenhpcbnkonpkc
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\njgpngjbkfdlohafinibpeeaolobljmk
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhijjefkkokfaiffkcemldacdabpeei
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\oipgijiceofkdddeceikmdjledafnehk
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pemfnmdbgcehmkfbgpcimghoopojjchp
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfogecppckimhabdpppalilellgoeoef
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjehmknlpomniikcbeldooclffegofcc
[!] Složka Smazáno : C:\ProgramData\ddcaefbgckeoinkciacamlecmmnfjebf
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\ProgramData\klpghljanbclanopclomjifjbfkgdfan
[!] Složka Smazáno : C:\ProgramData\ddcaefbgckeoinkciacamlecmmnfjebf
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\aehegibdeebpicpgdlejbfjpoajpnihh
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\hacopidmjdjongkaehgikkockhmcknfa
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\ibiiaimghkbhffgkkdogldehnidojjga
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\idgpnmonknjnojddfkpgkljpfnnfcklj
[!] Složka Smazáno : C:\Users\Administrator\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\Guest\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome SxS\User Data\Default\Extensions\jdgjpldbbdkfcfoegkmpkhoppnicaepe
[!] Složka Smazáno : C:\ProgramData\klpghljanbclanopclomjifjbfkgdfan
[!] Složka Smazáno : C:\ProgramData\ddcaefbgckeoinkciacamlecmmnfjebf
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_aehegibdeebpicpgdlejbfjpoajpnihh_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aehegibdeebpicpgdlejbfjpoajpnihh
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hacopidmjdjongkaehgikkockhmcknfa_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hacopidmjdjongkaehgikkockhmcknfa
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ibiiaimghkbhffgkkdogldehnidojjga_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_idgpnmonknjnojddfkpgkljpfnnfcklj_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aehegibdeebpicpgdlejbfjpoajpnihh
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hacopidmjdjongkaehgikkockhmcknfa
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aehegibdeebpicpgdlejbfjpoajpnihh
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hacopidmjdjongkaehgikkockhmcknfa
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aehegibdeebpicpgdlejbfjpoajpnihh
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_cjknneibmifpnmlkgfmcjhbajkehpbeb_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gamlmgkgpkoacendnhjdlccbijpkflbf_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_gdkpgbhhfnpjiembbpifcpfalfnflmop_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hacopidmjdjongkaehgikkockhmcknfa
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hibkhcnpkakjniplpfblaoikiggkopka_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ibpbofogepkkeoockhkfcgngjkimndlp_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_klpghljanbclanopclomjifjbfkgdfan_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nidiblpdmncdebogndoenhpcbnkonpkc_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_njgpngjbkfdlohafinibpeeaolobljmk_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_obhijjefkkokfaiffkcemldacdabpeei_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_oipgijiceofkdddeceikmdjledafnehk_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pemfnmdbgcehmkfbgpcimghoopojjchp_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pfogecppckimhabdpppalilellgoeoef_0.localstorage
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pjehmknlpomniikcbeldooclffegofcc_0.localstorage
Soubor Smazáno : C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Soubor Smazáno : C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb
Soubor Smazáno : C:\Windows\SysWOW64\conduitEngine.tmp
Soubor Smazáno : C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}Gw64.sys
Soubor Smazáno : C:\Windows\System32\drivers\{c83c7c03-36f9-4f8f-aa6d-c837575d4eca}w64.sys
Soubor Smazáno : C:\Users\okadmin\daemonprocess.txt
Soubor Smazáno : C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\0\user.js
Soubor Smazáno : C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences
Soubor Smazáno : C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\bprotector web data

***** [ Naplánované úlohy ] *****

Úloha Smazáno : BitGuard
Úloha Smazáno : GoforFilesUpdate

***** [ Zástupci ] *****


***** [ Registry ] *****

Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj
Klíč Smazáno : HKLM\SOFTWARE\Google\Chrome\Extensions\jbpkiefagocgkmemidfngdkamloieekf
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Main [bprotector start page]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Hodnota Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Prod.cap
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Klíč Smazáno : HKCU\Software\5b68ad1bc6ee513
Klíč Smazáno : HKLM\SOFTWARE\5b68ad1bc6ee513
Klíč Smazáno : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Klíč Smazáno : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{20E1481B-E285-4ABC-ADC7-AE24842B81CD}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Klíč Smazáno : HKLM\SOFTWARE\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{0194532A-A99C-4337-937E-2A452C8957BE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{BB9817CA-9B43-41EB-8706-44847957338D}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Klíč Smazáno : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{92E5039E-FF1E-4AFB-8F24-87592D20C383}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Klíč Smazáno : HKLM\SOFTWARE\Classes\TypeLib\{157B1AA6-3E5C-404A-9118-C1D91F537040}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B9507101-E464-4B3B-A4CB-291AAEDD94F2}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402C-BA80-02D8C59F9B1D}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403E-8DD8-394C54984B2C}
Klíč Smazáno : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{38122A36-83B2-46B8-B39A-EC72A4614A07}
Hodnota Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{46897C77-E7A6-4C33-BFFB-E9C2E2718942}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{46897C77-E7A6-4C33-BFFB-E9C2E2718942}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Hodnota Smazáno : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}]
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{0194532A-A99C-4337-937E-2A452C8957BE}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{BB9817CA-9B43-41EB-8706-44847957338D}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Klíč Smazáno : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Klíč Smazáno : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{7719A510-EA6F-44CC-901D-2059ACAE1902}
Klíč Smazáno : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E6521740-8096-4059-B836-C686C0AF8393}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
Klíč Smazáno : HKCU\Software\1ClickDownload
Klíč Smazáno : HKCU\Software\BABSOLUTION
Klíč Smazáno : HKCU\Software\BabylonToolbar
Klíč Smazáno : HKCU\Software\Conduit
Klíč Smazáno : HKCU\Software\DataMngr
Klíč Smazáno : HKCU\Software\filescout
Klíč Smazáno : HKCU\Software\GoforFiles
Klíč Smazáno : HKCU\Software\Optimizer Pro
Klíč Smazáno : HKCU\Software\RegisteredApplicationsEx
Klíč Smazáno : HKCU\Software\SweetIM
Klíč Smazáno : HKCU\Software\Tbccint_HKLM
Klíč Smazáno : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Klíč Smazáno : HKCU\Software\AppDataLow\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Klíč Smazáno : HKCU\Software\AppDataLow\Software\BackgroundContainer
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Conduit
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Crossrider
Klíč Smazáno : HKCU\Software\AppDataLow\Software\Mp3Tube
Klíč Smazáno : HKCU\Software\AppDataLow\Software\PriceGong
Klíč Smazáno : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Klíč Smazáno : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Klíč Smazáno : HKLM\SOFTWARE\{4A0F38A9-FE55-4B89-B73F-E60FDC0F72E9}
Klíč Smazáno : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Klíč Smazáno : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Klíč Smazáno : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Klíč Smazáno : HKLM\SOFTWARE\AskTBar
Klíč Smazáno : HKLM\SOFTWARE\Babylon
Klíč Smazáno : HKLM\SOFTWARE\BrowseFox
Klíč Smazáno : HKLM\SOFTWARE\Conduit
Klíč Smazáno : HKLM\SOFTWARE\DataMngr
Klíč Smazáno : HKLM\SOFTWARE\GoforFiles
Klíč Smazáno : HKLM\SOFTWARE\Mp3Tube
Klíč Smazáno : HKLM\SOFTWARE\SearchProtect
Klíč Smazáno : HKLM\SOFTWARE\SN.Booster
Klíč Smazáno : HKLM\SOFTWARE\SW-Booster
Klíč Smazáno : HKLM\SOFTWARE\SweetIM
Klíč Smazáno : HKLM\SOFTWARE\SPPDCOM
Klíč Smazáno : HKU\.DEFAULT\Software\AskPartnerNetwork
Klíč Smazáno : HKU\.DEFAULT\Software\AskToolbar
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F44DC3A-6E62-4961-A14B-95323C512F9B}_is1
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4820778D-AB0D-6D18-C316-52A6A0E1D507}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7DD5E91C-3864-77EC-7635-D14910C2A03E}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IspAssistant-Mp3Tube
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mobogenie
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{37476589-E48E-439E-A706-56189E2ED4C4}_is1
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C87834EB-A2A0-B9D4-AA9A-C263D1191051}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{594FD08C-0622-F9B8-CB02-7C1355D33CB8}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2616871-3463-BCEE-5AFA-73773317A381}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3DE8A1D7-C77F-E02A-70DD-31D29EC5B988}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{478472F9-9E09-492A-BDAB-42EE595EF1AD}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{76DEE3DC-2B8B-E212-2126-D31D9E73DFE4}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{98449C67-C7AF-BB53-112D-26C916814611}
Klíč Smazáno : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F5853CDF-2C63-6D1D-B286-CBB1CD5DFD62}
Data Smazáno : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL
Data Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\search~1\search~1\bin\spvc64~1.dll
Data Smazáno : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll

***** [ Prohlížeče ] *****

-\\ Internet Explorer v8.0.7600.16385

Nastavení Obnoveno : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v


-\\ Google Chrome v31.0.1650.63

[C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Smazáno [Search Provider] : hxxp://rts.dsrlte.com/?affID=na&q={searchTerms}
[C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Preferences] - Smazáno [Extension] : klpghljanbclanopclomjifjbfkgdfan

-\\ Comodo Dragon v


-\\ Chrome Canary v


*************************

AdwCleaner[R0].txt - [60977 bytů] - [05/07/2015 10:36:48]
AdwCleaner[S0].txt - [56858 bytů] - [05/07/2015 10:43:51]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [56917 bytů] ##########

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 05 črc 2015 10:42
od vyosek
:arrow: Stahnete Zoek.exe http://hijackthis.nl/smeenk/ a ulozte jej na plochu
  • Pokud pouzivate Win Vista ci W7, kliknete na Zoek pravym a dejte Run As Administrator ci Spustit jako spravce
  • Do okna vlozte skript nize
  • Kód: Vybrat vše

    autoclean;
    resethosts;
    emptyclsid;
    IEdefaults;
    FFdefaults;
    CHRdefaults;
    emptyIEcache;
    emptyFFcache;
    emptyCHRcache;
    emptyalltemp;
    emptyflash;
    emptyjava;
    emptyrecycle.bin;
    
  • Nasledne kliknete na Run Script
  • PC provede opravu, restartuje se a da Vam log, jeho obsah vlozte sem

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 17 črc 2015 02:35
od Taras
Bohužel jsem tu akci musel provést na dvakrát jelikož to poprvé trvalo déle než celý den a kousek
Tady je log z prvního pokusu:
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by okadmin on ne 05.07.2015 at 12:20:07,77.
Microsoft Windows 7 Home Premium 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\okadmin\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

5.7.2015 12:23:57 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\uTorrent deleted successfully
C:\PROGRA~2\COMMON~1\Nero deleted successfully
C:\PROGRA~2\COMMON~1\Symantec Shared deleted successfully
C:\Program Files\Google deleted successfully
C:\Users\okadmin\AppData\Roaming\{D94BA408-F110-488B-A65E-3AE7945F79E6} deleted successfully
C:\Users\okadmin\AppData\Local\cache deleted successfully
C:\Users\okadmin\AppData\Local\WMTools Downloaded Files deleted successfully


Tady je log z druhého pokusu, který byl dodělán do konce:

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by okadmin on źt 16.07.2015 at 13:51:32,39.
Microsoft Windows 7 Home Premium 6.1.7600 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\okadmin\Downloads\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2015-07-05-104237.log 1814 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\Users\okadmin\AppData\Local\CrashDumps deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{247D3255-88B7-4661-AAAF-9D06DC47B52F} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B55BCEF8-B57D-4FA9-A64A-07AD94880A07} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_USERS\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:

Added to C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js:

Added to C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Windows Live SkyDrive deleted
C:\Users\okadmin\AppData\LocalLow\{2072AF10-4E1C-060B-4945-BFDC62D1402D} deleted
C:\Users\okadmin\AppData\LocalLow\{38805716-8FDE-542E-00C9-FEF19EB3A5F0} deleted
C:\Users\okadmin\AppData\LocalLow\{502EECA3-EDBE-CC10-B597-56445AB669A5} deleted
C:\Users\okadmin\AppData\LocalLow\{53A6884D-5022-A53A-5F57-A0489B6BE404} deleted
C:\Users\okadmin\AppData\LocalLow\{545C3BB8-B491-0EE9-7DD1-91385B2B9C7E} deleted
C:\Users\okadmin\AppData\LocalLow\{587536BD-23C2-7B9F-F5EF-16BB9ABE5D6D} deleted
C:\Users\okadmin\AppData\LocalLow\{7898F832-26E0-0E3D-EFE5-FA4ABB3C25FC} deleted
C:\Users\okadmin\AppData\LocalLow\{8737F302-AE3E-36F4-AF09-3D0C3B487F4D} deleted
C:\Users\okadmin\AppData\LocalLow\{88F30D10-53B7-E3C2-6001-5F84BFD02250} deleted
C:\Users\okadmin\AppData\LocalLow\{A161CAE6-0650-C137-B89B-CF7AFEB888A9} deleted
C:\Users\okadmin\AppData\LocalLow\{A32178BB-B337-D0AC-254E-F3141AD9C8DE} deleted
C:\Users\okadmin\AppData\LocalLow\{CAC5FFBE-4D3D-A7AC-E9BB-4CD9E3544758} deleted
C:\Users\okadmin\AppData\LocalLow\{D2CACE90-C75A-D502-3E6E-1DB256A23072} deleted
C:\Users\okadmin\AppData\LocalLow\{F2D6111C-F491-861E-FF94-DD68B4EA8FCB} deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\{502EECA3-EDBE-CC10-B597-56445AB669A5} deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\{7898F832-26E0-0E3D-EFE5-FA4ABB3C25FC} deleted
C:\Windows\sysWoW64\config\systemprofile\AppData\LocalLow\{CAC5FFBE-4D3D-A7AC-E9BB-4CD9E3544758} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{2072AF10-4E1C-060B-4945-BFDC62D1402D} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{38805716-8FDE-542E-00C9-FEF19EB3A5F0} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{53A6884D-5022-A53A-5F57-A0489B6BE404} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{545C3BB8-B491-0EE9-7DD1-91385B2B9C7E} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{587536BD-23C2-7B9F-F5EF-16BB9ABE5D6D} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{8737F302-AE3E-36F4-AF09-3D0C3B487F4D} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{88F30D10-53B7-E3C2-6001-5F84BFD02250} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{A161CAE6-0650-C137-B89B-CF7AFEB888A9} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{A32178BB-B337-D0AC-254E-F3141AD9C8DE} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{D2CACE90-C75A-D502-3E6E-1DB256A23072} deleted
C:\Users\okadmin\AppData\Local\Packages\windows_ie_ac_001\AC\{F2D6111C-F491-861E-FF94-DD68B4EA8FCB} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{502EECA3-EDBE-CC10-B597-56445AB669A5} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{7898F832-26E0-0E3D-EFE5-FA4ABB3C25FC} deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\Packages\windows_ie_ac_001\AC\{CAC5FFBE-4D3D-A7AC-E9BB-4CD9E3544758} deleted
C:\Users\okadmin\.android deleted
C:\PROGRA~3\PDFConverotEr deleted
C:\PROGRA~2\Wondershare deleted
C:\PROGRA~2\COMMON~1\Wondershare deleted
C:\extensions deleted
C:\Users\okadmin\AppData\Roaming\appdataFr2.bin deleted
C:\Users\okadmin\AppData\Roaming\Wondershare deleted
C:\PROGRA~3\Excellent4App deleted
C:\PROGRA~3\InstallMate deleted
C:\Users\okadmin\AppData\Local\mbt-actwiz.log deleted
C:\Users\okadmin\AppData\Local\avgchrome deleted
C:\Users\okadmin\AppData\Local\Wondershare deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 deleted
C:\windows\SysNative\Tasks\avastBCLRestartS-1-5-21-1641521609-2111440031-3658305165-1000 deleted
C:\Windows\AppPatch\AppPatch64\SPVCLdr64.dll deleted
C:\windows\SysNative\tasks\Torntv 2-codedownloader deleted
C:\Users\wangjihua deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\Windows\Syswow64\GroupPolicy\gpt.ini deleted
C:\Windows\SysWow64\searchplugins deleted
C:\Windows\SysWow64\Extensions deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\0
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"wrc@avast.com"="C:\Program Files\AVAST Software\Avast\WebRep\FF" [28.01.2015 11:10]
[HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions]
"smartwebprinting@hp.com"="C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3" [10.10.2011 22:14]

==== Firefox Extensions ======================

ExtDir: C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions
- Torntv 3 - %ExtDir%\trtv3@trtv.com.xpi

==== Firefox Plugins ======================


==== Deleted Firefox Extensions ======================

C:\Users\okadmin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\trtv3@trtv.com.xpi deleted

==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Administrator\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Administrator\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\Guest\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\Guest\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\HomeGroupUser$\AppData\Local\Comodo\Dragon deleted
Fake profile C:\Users\okadmin\AppData\Local\Google\Chrome SxS deleted
Fake profile C:\Users\okadmin\AppData\Local\Comodo\Dragon deleted

==== Chromium Look ======================

Google Chrome Version: 31.0.1650.63

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[16.12.2014 23:49]

AdBlock - okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
avast Online Security - okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Delta Toolbar - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde
PDFConverotEr - C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpghljanbclanopclomjifjbfkgdfan

==== Chromium Startpages ======================

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://www.google.com",
"urls_to_restore_on_startup": [ "http://www.google.com" ]


==== Chromium Fix ======================

C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\eooncjejnppfjjklapaamhcdmjbilmde deleted successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\klpghljanbclanopclomjifjbfkgdfan deleted successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_klpghljanbclanopclomjifjbfkgdfan_0.localstorage deleted successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_klpghljanbclanopclomjifjbfkgdfan_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
"Start Page"="https://www.seznam.cz/?clid=22668"
"Search Bar"="https://www.seznam.cz/?clid=22668"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="https://www.seznam.cz/?clid=22668"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"
{11BD6EA1-296E-4EC0-A6EA-AAFAFC272044} Mapy.cz Url="http://www.mapy.cz/?query={searchTerms} ... arch_12454"
{15C4DF55-4B67-495A-A3D3-A497C4A49EE0} Seznam Url="http://search.seznam.cz/?sourceid=quick ... earchTerms}"
{2B196B72-D14E-4BD7-9AA2-87F9E773251B} Zbo§ˇ.cz Url="http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454"
{66DBD706-1C61-4980-B510-9EC7478C4CED} Encyklopedie Seznam Url="http://encyklopedie.seznam.cz/search?q= ... arch_12454"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... KB_csCZ513"
{6CB41F7D-A3FC-484C-A5AC-029990341B04} Firmy.cz Url="http://www.firmy.cz/?q={searchTerms}&so ... arch_12454"
{7D190EB7-6B70-4D6F-B3C1-16B6BE658952} Slovnˇk EN/CZ Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
{812814B3-8CE5-427F-8A7E-6E59375CD36E} Slovnˇk CZ/EN Url="http://slovnik.seznam.cz/?q={searchTerm ... arch_12454"
{8946585C-AA7C-4618-A582-1EE6FD2D8CC4} Novinky.cz Url="http://www.novinky.cz/hledej?w={searchT ... arch_12454"
{CCA233DC-542E-4F99-998C-6099875144DC} Seznam Url="http://search.seznam.cz/?q={searchTerms ... arch_12454"
{D16658FF-1364-4926-9E8E-0CA83A4CA452} Bing Url="http://www.bing.com/search?q={searchTer ... -SearchBox"
{D6550F91-3483-40E4-8DAC-94A140C97EA3} Wikipedia Url="http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}"
{EDED2F62-3D30-479D-A055-3C43D6699DE5} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"

==== Reset Google Chrome ======================

C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\chromepreferences was reset successfully
C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\44050ae1-8764-4a3d-a8a7-2dfa07b57de8 deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\53c9e73c-d6ba-4d8c-a411-671f1f7eb065 deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_CURRENT_USER\Software\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\okadmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Chrome Cache ======================

C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=576 folders=146 95252053 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\okadmin\AppData\Local\Temp will be emptied at reboot
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\okadmin\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\okadmin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found

==== EOF on p  17.07.2015 at 3:28:13,85 ======================

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 17 črc 2015 08:22
od vyosek

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 17 črc 2015 17:06
od Taras
Nemusíte prosit :D to já jsem neskutečně vděčný za to co pro mě děláte! :)

Tady log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by okadmin (administrator) on OKADMIN-HP on 17-07-2015 17:46:00
Running from C:\Users\okadmin\Desktop
Loaded Profiles: okadmin (Available Profiles: okadmin)
Platform: Windows 7 Home Premium (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtVOsd\RtVOsd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\okadmin\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2097960 2010-04-23] (Synaptics Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6245408 2010-05-26] (Realtek Semiconductor)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602680 2010-07-02] (Hewlett-Packard Company)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227648 2015-03-30] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Run: [HPAdvisorDock] => C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53288576 2015-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: H - H:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: I - I:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {0bbe27ed-16e1-11e2-be54-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {1e632d38-c531-11e0-931a-60eb694199ae} - "H:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {5dd07d77-17b5-11e2-901b-70f39576171f} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d0b-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d2c-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {78ecd0c0-9da7-11e0-8849-806e6f6e6963} - G:\RunGame.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ed-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ff-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {a74f30f2-c1de-11e0-9022-60eb694199ae} - H:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {b7c560c0-bd3b-11e0-b093-60eb694199ae} - I:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {d55f4470-8c74-11e0-a930-60eb694199ae} - F:\AutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {e71362c0-9047-11e0-8641-806e6f6e6963} - F:\Autorun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2011-10-10]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2014-12-16] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.seznam.cz/?clid=22668
SearchScopes: HKLM -> {D16658FF-1364-4926-9E8E-0CA83A4CA452} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM -> {D6550F91-3483-40E4-8DAC-94A140C97EA3} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKLM-x32 -> {D16658FF-1364-4926-9E8E-0CA83A4CA452} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM-x32 -> {D6550F91-3483-40E4-8DAC-94A140C97EA3} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {11BD6EA1-296E-4EC0-A6EA-AAFAFC272044} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = http://search.seznam.cz/?sourceid=quick ... earchTerms}
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {2B196B72-D14E-4BD7-9AA2-87F9E773251B} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {66DBD706-1C61-4980-B510-9EC7478C4CED} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {6CB41F7D-A3FC-484C-A5AC-029990341B04} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {7D190EB7-6B70-4D6F-B3C1-16B6BE658952} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {812814B3-8CE5-427F-8A7E-6E59375CD36E} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {8946585C-AA7C-4618-A582-1EE6FD2D8CC4} URL = http://www.novinky.cz/hledej?w={searchT ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {CCA233DC-542E-4F99-998C-6099875144DC} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {D16658FF-1364-4926-9E8E-0CA83A4CA452} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {D6550F91-3483-40E4-8DAC-94A140C97EA3} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKU\S-1-5-21-1641521609-2111440031-3658305165-1000 -> {EDED2F62-3D30-479D-A055-3C43D6699DE5} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2014-12-16] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-15] (Sun Microsystems, Inc.)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-01-03] (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2014-12-16] (AVAST Software)
BHO-x32: Pomocník pro přihlášení ke službě Windows Live -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2010-08-15] (Sun Microsystems, Inc.)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-08-15] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-08-15] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-08-15] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-08-15] (Microsoft Corporation)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2010-08-14] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 217.66.178.100 217.66.178.205 217.66.190.211 217.66.190.160
Tcpip\..\Interfaces\{8493175C-A22C-4867-A4CE-8F712B714D46}: [DhcpNameServer] 217.66.178.100 217.66.178.205 217.66.190.211 217.66.190.160

FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-04-17] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2012-01-03] (Adobe Systems Inc.)
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011-10-10]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-05-20]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Docs) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-13]
CHR Extension: (Google Drive) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-13]
CHR Extension: (YouTube) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-13]
CHR Extension: (Adblock Plus) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-06-18]
CHR Extension: (Google Search) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-13]
CHR Extension: (AdBlock) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-06-18]
CHR Extension: (Avast Online Security) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-10-13]
CHR Extension: (Google Wallet) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Gmail) - C:\Users\okadmin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-13]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-12-16]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-12-16] (AVAST Software)
R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed]
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-07-02] ()
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2011-03-04] (Hewlett-Packard Company) [File not signed]
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 RtVOsdService; C:\Program Files\Realtek\RtVOsd\RtVOsdService.exe [315392 2010-04-19] (Realtek Semiconductor Corp.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-12-16] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-12-16] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-12-16] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-12-16] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-12-16] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-12-16] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-12-16] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-12-16] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2011-07-07] () [File not signed]
R3 LgBttPort; C:\Windows\System32\DRIVERS\lgbtpt64.sys [16384 2009-09-29] (LG Electronics Inc.)
R3 lgbusenum; C:\Windows\System32\DRIVERS\lgbtbs64.sys [14848 2009-09-29] (LG Electronics Inc.)
R3 LGVMODEM; C:\Windows\System32\DRIVERS\lgvmdm64.sys [17408 2009-09-29] (LG Electronics Inc.)
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2011-07-07] () [File not signed]
S3 PcaSp60; C:\Windows\SysWOW64\DRIVERS\PcaSp60.sys [38912 2010-05-19] (Printing Communications Assoc., Inc. (PCAUSA))
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [513080 2011-06-06] () [File not signed]
S3 usbbus; C:\Windows\System32\DRIVERS\lgx64bus.sys [17920 2008-11-19] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgx64diag.sys [27136 2008-11-19] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgx64modem.sys [33792 2008-11-19] (LG Electronics Inc.)
U3 agh7g0hp; C:\Windows\System32\Drivers\agh7g0hp.sys [0 ] (Intel Corporation) <==== ATTENTION (zero byte File/Folder)
S3 BTMCOM; System32\Drivers\btmcom.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 17:46 - 2015-07-17 17:46 - 00020272 _____ C:\Users\okadmin\Desktop\FRST.txt
2015-07-17 17:45 - 2015-07-17 17:46 - 00000000 ____D C:\FRST
2015-07-17 17:43 - 2015-07-17 17:44 - 00112640 _____ (forum.viry.cz) C:\Users\okadmin\Desktop\FRSTLauncher.exe
2015-07-17 17:30 - 2015-07-17 17:29 - 02133504 _____ (Farbar) C:\Users\okadmin\Desktop\FRST64.exe
2015-07-17 17:29 - 2015-07-17 17:29 - 02133504 _____ (Farbar) C:\Users\okadmin\Downloads\FRST64.exe
2015-07-17 03:27 - 2015-07-17 03:27 - 00001242 _____ C:\Windows\PFRO.log
2015-07-17 02:50 - 2015-07-16 13:51 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 14:06 - 2015-07-05 12:42 - 00001814 _____ C:\zoek-results2015-07-05-104237.log
2015-07-10 18:12 - 2015-07-10 18:12 - 00038043 _____ C:\Users\okadmin\Downloads\červenec 2015 (1).ods
2015-07-10 17:17 - 2015-07-17 17:35 - 00000280 _____ C:\Windows\setupact.log
2015-07-10 17:17 - 2015-07-10 17:17 - 00000000 _____ C:\Windows\setuperr.log
2015-07-06 22:01 - 2015-07-06 22:18 - 00047104 _____ C:\Users\okadmin\Downloads\10-objednavkovy-formular.xls
2015-07-05 12:23 - 2015-07-17 03:28 - 00020576 _____ C:\zoek-results.log
2015-07-05 12:19 - 2015-07-17 00:35 - 00000000 ____D C:\zoek_backup
2015-07-05 12:19 - 2015-07-05 12:19 - 01308672 _____ C:\Users\okadmin\Downloads\zoek.exe
2015-07-05 11:08 - 2015-07-05 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Codec Pack
2015-07-05 11:08 - 2015-07-05 11:08 - 00000000 ____D C:\Program Files (x86)\Codec Pack - All In 1
2015-07-05 11:08 - 2015-07-05 11:07 - 00737280 _____ (Indigo Rose Corporation) C:\Windows\iun6002.exe
2015-07-05 11:07 - 2015-07-05 11:07 - 00450560 _____ C:\Users\okadmin\Downloads\Codecsallin1 (1).exe
2015-07-05 11:04 - 2015-07-05 11:07 - 18351536 _____ C:\Users\okadmin\Downloads\Codecsallin1.exe
2015-07-05 10:36 - 2015-07-05 10:45 - 00000000 ____D C:\AdwCleaner
2015-07-05 10:34 - 2015-07-05 10:34 - 02244096 _____ C:\Users\okadmin\Desktop\adwcleaner_4.207.exe
2015-07-05 09:43 - 2015-07-05 09:44 - 00000000 ____D C:\rsit
2015-07-05 09:43 - 2015-07-05 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-07-05 01:12 - 2015-07-05 01:12 - 00000000 ____D C:\Users\okadmin\Tracing
2015-07-04 21:45 - 2015-07-04 21:45 - 00000000 ____D C:\Users\okadmin\AppData\Local\Skype
2015-07-04 21:36 - 2015-07-04 21:36 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2015-07-04 21:36 - 2015-07-04 21:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-07-04 21:35 - 2015-07-04 21:36 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-07-04 21:30 - 2015-07-04 21:31 - 01222144 _____ C:\Users\okadmin\Downloads\RSITx64.exe
2015-07-04 21:14 - 2015-07-04 21:17 - 40426624 _____ (Skype Technologies S.A.) C:\Users\okadmin\Downloads\SkypeSetupFull.exe
2015-07-04 10:55 - 2015-07-04 10:55 - 00002798 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-07-04 10:55 - 2015-07-04 10:55 - 00000782 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-07-04 10:55 - 2015-07-04 10:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-07-04 10:55 - 2015-07-04 10:55 - 00000000 ____D C:\Program Files\CCleaner
2015-07-04 10:53 - 2015-07-04 10:53 - 06565352 _____ (Piriform Ltd) C:\Users\okadmin\Downloads\ccsetup507pro.exe
2015-07-01 16:32 - 2015-07-17 17:41 - 00000000 ____D C:\Users\okadmin\AppData\Roaming\Skype
2015-07-01 16:32 - 2015-07-04 21:42 - 00000000 ____D C:\ProgramData\Skype
2015-06-25 08:32 - 2015-06-25 08:32 - 00000000 ____D C:\ProgramData\GRETECH
2015-06-21 21:20 - 2015-07-07 21:03 - 00036887 _____ C:\Users\okadmin\Downloads\červenec 2015 .ods

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-17 17:44 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-17 17:44 - 2009-07-14 06:45 - 00023024 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-17 17:41 - 2014-02-24 23:27 - 01242490 _____ C:\Windows\WindowsUpdate.log
2015-07-17 17:35 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-17 17:27 - 2010-08-15 07:48 - 00631292 _____ C:\Windows\system32\perfh005.dat
2015-07-17 17:27 - 2010-08-15 07:48 - 00121914 _____ C:\Windows\system32\perfc005.dat
2015-07-17 17:27 - 2009-07-14 07:13 - 01470062 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-17 17:24 - 2012-01-23 22:20 - 00003986 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{A7A48ADA-853C-4D98-9477-6908C63D7BF9}
2015-07-17 11:04 - 2015-01-21 13:18 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-17 06:41 - 2012-06-26 10:00 - 00000000 ____D C:\Program Files (x86)\MyDefrag v4.3.1
2015-07-17 03:30 - 2011-06-21 18:53 - 00000000 ____D C:\Users\okadmin\AppData\Roaming\uTorrent
2015-07-17 03:28 - 2014-02-02 02:11 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-07-16 23:40 - 2014-05-20 13:51 - 00000000 ____D C:\Users\okadmin\AppData\Local\Comodo
2015-07-16 23:40 - 2014-05-20 13:51 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Google
2015-07-16 23:40 - 2014-05-20 13:51 - 00000000 ____D C:\Users\HomeGroupUser$\AppData\Local\Comodo
2015-07-16 23:40 - 2014-05-20 13:51 - 00000000 ____D C:\Users\Guest\AppData\Local\Google
2015-07-16 23:40 - 2014-05-20 13:51 - 00000000 ____D C:\Users\Guest\AppData\Local\Comodo
2015-07-16 23:40 - 2012-07-20 17:16 - 00000000 ____D C:\Users\okadmin\AppData\Local\Google
2015-07-16 23:39 - 2014-05-20 13:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Google
2015-07-16 23:39 - 2014-05-20 13:51 - 00000000 ____D C:\Users\Administrator\AppData\Local\Comodo
2015-07-16 22:48 - 2010-12-11 14:08 - 00000000 ____D C:\Users\okadmin
2015-07-16 22:48 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-07-16 22:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy
2015-07-16 14:06 - 2015-01-21 13:18 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-16 14:06 - 2012-07-20 17:16 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-16 14:06 - 2012-07-20 17:16 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-16 13:50 - 2013-12-29 17:55 - 00000000 ____D C:\Users\okadmin\Documents\Cestovatelské deníky
2015-07-10 17:19 - 2014-10-13 20:30 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2015-07-05 14:05 - 2015-01-30 09:46 - 00000000 ____D C:\Users\okadmin\Desktop\Mamka
2015-07-04 20:51 - 2009-07-14 04:34 - 00000524 _____ C:\Windows\win.ini
2015-07-04 20:50 - 2012-06-26 10:00 - 00004138 _____ C:\Windows\System32\Tasks\MyDefrag v4.3.1 Monthly
2015-07-04 20:50 - 2012-06-26 10:00 - 00003458 _____ C:\Windows\System32\Tasks\MyDefrag v4.3.1 Daily
2015-07-04 20:46 - 2011-08-03 22:06 - 00000000 ____D C:\ProgramData\LightScribe
2015-07-04 10:57 - 2011-06-01 11:48 - 00000000 ____D C:\Users\okadmin\AppData\Roaming\DAEMON Tools Lite
2015-07-03 00:14 - 2013-02-17 14:45 - 00000000 ____D C:\Users\okadmin\Documents\Literatura
2015-07-01 17:12 - 2015-04-30 08:28 - 00151040 _____ C:\Users\okadmin\Downloads\Docházka 2015.xls
2015-06-25 09:24 - 2012-02-22 01:51 - 00003198 _____ C:\Windows\System32\Tasks\HPCeeScheduleForokadmin
2015-06-25 09:24 - 2012-02-22 01:51 - 00000340 _____ C:\Windows\Tasks\HPCeeScheduleForokadmin.job
2015-06-23 16:09 - 2013-03-31 23:09 - 00001141 _____ C:\Users\okadmin\AppData\Roaming\Microsoft\Windows\Start Menu\GOM Player.lnk
2015-06-23 16:09 - 2013-03-31 23:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOM Player

==================== Files in the root of some directories =======

2012-01-02 13:53 - 2015-04-09 13:12 - 0007168 _____ () C:\Users\okadmin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-01-30 18:14 - 2012-01-30 18:14 - 0004096 ____H () C:\Users\okadmin\AppData\Local\keyfile3.drm
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p02].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p03].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p04].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p05].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p06].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p07].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p08].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p09].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p10].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p11].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p12].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p13].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p14].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p15].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p16].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p17].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p18].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p19].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p20].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p21].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p22].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p23].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p24].bmp
2014-12-04 13:31 - 2014-12-04 13:31 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p25].bmp
2014-12-04 13:31 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p26].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p27].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p28].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p29].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p30].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p31].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p32].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p33].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p34].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p35].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p36].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p37].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p38].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p39].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p40].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p41].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p42].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p43].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p44].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p45].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p46].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p47].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p48].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p49].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p50].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p51].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p52].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p53].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p54].bmp
2014-12-04 13:32 - 2014-12-04 13:32 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p55].bmp
2014-12-04 13:33 - 2014-12-04 13:33 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p56].bmp
2014-12-04 13:33 - 2014-12-04 13:33 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p57].bmp
2014-12-04 13:33 - 2014-12-04 13:33 - 2315574 _____ () C:\Users\okadmin\AppData\Local\[j0002]-[p58].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p08].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p09].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p10].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p11].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p12].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p13].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p14].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p15].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p16].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p17].bmp
2014-01-16 19:24 - 2014-01-16 19:24 - 2428470 _____ () C:\Users\okadmin\AppData\Local\[j0006]-[p18].bmp
2011-10-10 21:03 - 2014-09-17 10:00 - 0002916 _____ () C:\ProgramData\hpzinstall.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-08-14 23:47 - 2010-08-14 23:47 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-08-14 23:40 - 2010-08-14 23:41 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-08-17 01:38 - 2010-08-17 01:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-08-14 23:39 - 2010-08-14 23:40 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-08-14 23:41 - 2010-08-14 23:47 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\HPCeeScheduleForokadmin.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\okadmin\Desktop" je 7583 MB.


***** Startup Programs *****

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
"C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor
"C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
"C:\Users\okadmin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED [x]


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000001


==================== End Of Log ==============================

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 17 črc 2015 19:41
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53288576 2015-06-29] (Skype Technologies S.A.)
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableLockWorkstation] 0
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableChangePassword] 0
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: H - H:\USBAutoRun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: I - I:\USBAutoRun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {0bbe27ed-16e1-11e2-be54-60eb694199ae} - H:\Autorun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {1e632d38-c531-11e0-931a-60eb694199ae} - "H:\WD SmartWare.exe" autoplay=true
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {5dd07d77-17b5-11e2-901b-70f39576171f} - H:\Autorun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d0b-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d2c-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {78ecd0c0-9da7-11e0-8849-806e6f6e6963} - G:\RunGame.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ed-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ff-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {a74f30f2-c1de-11e0-9022-60eb694199ae} - H:\USBAutoRun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {b7c560c0-bd3b-11e0-b093-60eb694199ae} - I:\USBAutoRun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {d55f4470-8c74-11e0-a930-60eb694199ae} - F:\AutoRun.exe
    HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {e71362c0-9047-11e0-8641-806e6f6e6963} - F:\Autorun.exe
    
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    
    S3 BTMCOM; System32\Drivers\btmcom.sys [X]
    S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
    S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
    S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
    
    2015-07-17 17:46 - 2015-07-17 17:46 - 00020272 _____ C:\Users\okadmin\Desktop\FRST.txt
    2015-07-17 17:43 - 2015-07-17 17:44 - 00112640 _____ (forum.viry.cz) C:\Users\okadmin\Desktop\FRSTLauncher.exe
    2015-07-17 03:27 - 2015-07-17 03:27 - 00001242 _____ C:\Windows\PFRO.log
    2015-07-17 02:50 - 2015-07-16 13:51 - 00024064 _____ C:\Windows\zoek-delete.exe
    2015-07-16 14:06 - 2015-07-05 12:42 - 00001814 _____ C:\zoek-results2015-07-05-104237.log
    2015-07-10 17:17 - 2015-07-17 17:35 - 00000280 _____ C:\Windows\setupact.log
    2015-07-10 17:17 - 2015-07-10 17:17 - 00000000 _____ C:\Windows\setuperr.log
    2015-07-05 12:23 - 2015-07-17 03:28 - 00020576 _____ C:\zoek-results.log
    2015-07-05 12:19 - 2015-07-17 00:35 - 00000000 ____D C:\zoek_backup
    2015-07-05 12:19 - 2015-07-05 12:19 - 01308672 _____ C:\Users\okadmin\Downloads\zoek.exe
    2015-07-05 10:36 - 2015-07-05 10:45 - 00000000 ____D C:\AdwCleaner
    2015-07-05 10:34 - 2015-07-05 10:34 - 02244096 _____ C:\Users\okadmin\Desktop\adwcleaner_4.207.exe
    2015-07-05 09:43 - 2015-07-05 09:44 - 00000000 ____D C:\rsit
    2015-07-05 09:43 - 2015-07-05 09:43 - 00000000 ____D C:\Program Files\trend micro
    2015-07-04 21:30 - 2015-07-04 21:31 - 01222144 _____ C:\Users\okadmin\Downloads\RSITx64.exe
    2015-07-04 10:53 - 2015-07-04 10:53 - 06565352 _____ (Piriform Ltd) C:\Users\okadmin\Downloads\ccsetup507pro.exe
    2011-10-10 21:03 - 2014-09-17 10:00 - 0002916 _____ () C:\ProgramData\hpzinstall.log
    2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
    2010-08-14 23:47 - 2010-08-14 23:47 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
    2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
    2010-08-14 23:40 - 2010-08-14 23:41 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
    2010-08-17 01:38 - 2010-08-17 01:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
    2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
    2010-08-14 23:39 - 2010-08-14 23:40 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
    2010-08-14 23:41 - 2010-08-14 23:47 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
    2010-08-17 01:39 - 2010-08-17 01:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log
    
    Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\Windows\Tasks\HPCeeScheduleForokadmin.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
    Task: {04D96C0A-305A-4C91-9C96-A98B3ED69639} - \Torntv 2-codedownloader No Task File <==== ATTENTION
    Task: {4528444E-49CD-43FA-869F-0B1E5A349C02} - \avastBCLRestartS-1-5-21-1641521609-2111440031-3658305165-1000 No Task File <==== ATTENTION
    
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
    DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 18 črc 2015 01:48
od Taras
Fix result of Farbar Recovery Scan Tool (x64) Version:13-07-2015
Ran by okadmin at 2015-07-18 02:43:08 Run:1
Running from C:\Users\okadmin\Desktop
Loaded Profiles: okadmin (Available Profiles: okadmin)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53288576 2015-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: H - H:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: I - I:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {0bbe27ed-16e1-11e2-be54-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {1e632d38-c531-11e0-931a-60eb694199ae} - "H:\WD SmartWare.exe" autoplay=true
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {5dd07d77-17b5-11e2-901b-70f39576171f} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d0b-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {74f14d2c-7b69-11e3-ac25-70f39576171f} - I:\setup.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {78ecd0c0-9da7-11e0-8849-806e6f6e6963} - G:\RunGame.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ed-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {916ab4ff-169a-11e2-b4cf-60eb694199ae} - H:\Autorun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {a74f30f2-c1de-11e0-9022-60eb694199ae} - H:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {b7c560c0-bd3b-11e0-b093-60eb694199ae} - I:\USBAutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {d55f4470-8c74-11e0-a930-60eb694199ae} - F:\AutoRun.exe
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\...\MountPoints2: {e71362c0-9047-11e0-8641-806e6f6e6963} - F:\Autorun.exe

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\.DEFAULT -> {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

S3 BTMCOM; System32\Drivers\btmcom.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]

2015-07-17 17:46 - 2015-07-17 17:46 - 00020272 _____ C:\Users\okadmin\Desktop\FRST.txt
2015-07-17 17:43 - 2015-07-17 17:44 - 00112640 _____ (forum.viry.cz) C:\Users\okadmin\Desktop\FRSTLauncher.exe
2015-07-17 03:27 - 2015-07-17 03:27 - 00001242 _____ C:\Windows\PFRO.log
2015-07-17 02:50 - 2015-07-16 13:51 - 00024064 _____ C:\Windows\zoek-delete.exe
2015-07-16 14:06 - 2015-07-05 12:42 - 00001814 _____ C:\zoek-results2015-07-05-104237.log
2015-07-10 17:17 - 2015-07-17 17:35 - 00000280 _____ C:\Windows\setupact.log
2015-07-10 17:17 - 2015-07-10 17:17 - 00000000 _____ C:\Windows\setuperr.log
2015-07-05 12:23 - 2015-07-17 03:28 - 00020576 _____ C:\zoek-results.log
2015-07-05 12:19 - 2015-07-17 00:35 - 00000000 ____D C:\zoek_backup
2015-07-05 12:19 - 2015-07-05 12:19 - 01308672 _____ C:\Users\okadmin\Downloads\zoek.exe
2015-07-05 10:36 - 2015-07-05 10:45 - 00000000 ____D C:\AdwCleaner
2015-07-05 10:34 - 2015-07-05 10:34 - 02244096 _____ C:\Users\okadmin\Desktop\adwcleaner_4.207.exe
2015-07-05 09:43 - 2015-07-05 09:44 - 00000000 ____D C:\rsit
2015-07-05 09:43 - 2015-07-05 09:43 - 00000000 ____D C:\Program Files\trend micro
2015-07-04 21:30 - 2015-07-04 21:31 - 01222144 _____ C:\Users\okadmin\Downloads\RSITx64.exe
2015-07-04 10:53 - 2015-07-04 10:53 - 06565352 _____ (Piriform Ltd) C:\Users\okadmin\Downloads\ccsetup507pro.exe
2011-10-10 21:03 - 2014-09-17 10:00 - 0002916 _____ () C:\ProgramData\hpzinstall.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log
2010-08-14 23:47 - 2010-08-14 23:47 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log
2010-08-14 23:40 - 2010-08-14 23:41 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2010-08-17 01:38 - 2010-08-17 01:38 - 0000032 _____ () C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000032 _____ () C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log
2010-08-14 23:39 - 2010-08-14 23:40 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2010-08-14 23:41 - 2010-08-14 23:47 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
2010-08-17 01:39 - 2010-08-17 01:39 - 0000105 _____ () C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\HPCeeScheduleForokadmin.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: {04D96C0A-305A-4C91-9C96-A98B3ED69639} - \Torntv 2-codedownloader No Task File <==== ATTENTION
Task: {4528444E-49CD-43FA-869F-0B1E5A349C02} - \avastBCLRestartS-1-5-21-1641521609-2111440031-3658305165-1000 No Task File <==== ATTENTION

DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite
DeleteKey: HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent

Hosts:
EmptyTemp:
Reboot:
End
*****************

Processes closed successfully.
Restore point was successfully created.
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Skype => value removed successfully
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableLockWorkstation => value removed successfully
HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\Software\Microsoft\Windows\CurrentVersion\Policies\system\\DisableChangePassword => value removed successfully
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H" => key removed successfully
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\I" => key removed successfully
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0bbe27ed-16e1-11e2-be54-60eb694199ae}" => key removed successfully
HKCR\CLSID\{0bbe27ed-16e1-11e2-be54-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1e632d38-c531-11e0-931a-60eb694199ae}" => key removed successfully
HKCR\CLSID\{1e632d38-c531-11e0-931a-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5dd07d77-17b5-11e2-901b-70f39576171f}" => key removed successfully
HKCR\CLSID\{5dd07d77-17b5-11e2-901b-70f39576171f} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74f14d0b-7b69-11e3-ac25-70f39576171f}" => key removed successfully
HKCR\CLSID\{74f14d0b-7b69-11e3-ac25-70f39576171f} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74f14d2c-7b69-11e3-ac25-70f39576171f}" => key removed successfully
HKCR\CLSID\{74f14d2c-7b69-11e3-ac25-70f39576171f} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{78ecd0c0-9da7-11e0-8849-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{78ecd0c0-9da7-11e0-8849-806e6f6e6963} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{916ab4ed-169a-11e2-b4cf-60eb694199ae}" => key removed successfully
HKCR\CLSID\{916ab4ed-169a-11e2-b4cf-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{916ab4ff-169a-11e2-b4cf-60eb694199ae}" => key removed successfully
HKCR\CLSID\{916ab4ff-169a-11e2-b4cf-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a74f30f2-c1de-11e0-9022-60eb694199ae}" => key removed successfully
HKCR\CLSID\{a74f30f2-c1de-11e0-9022-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b7c560c0-bd3b-11e0-b093-60eb694199ae}" => key removed successfully
HKCR\CLSID\{b7c560c0-bd3b-11e0-b093-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d55f4470-8c74-11e0-a930-60eb694199ae}" => key removed successfully
HKCR\CLSID\{d55f4470-8c74-11e0-a930-60eb694199ae} => key not found.
"HKU\S-1-5-21-1641521609-2111440031-3658305165-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e71362c0-9047-11e0-8641-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{e71362c0-9047-11e0-8641-806e6f6e6963} => key not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4b71-B0A3-3D82E62A6909}" => key removed successfully
HKCR\CLSID\{483830EE-A4CD-4b71-B0A3-3D82E62A6909} => key not found.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
BTMCOM => Service removed successfully
Huawei => Service removed successfully
hwdatacard => Service removed successfully
hwusbdev => Service removed successfully
"C:\Users\okadmin\Desktop\FRST.txt" => File/Folder not found.
C:\Users\okadmin\Desktop\FRSTLauncher.exe => moved successfully.
C:\Windows\PFRO.log => moved successfully.
C:\Windows\zoek-delete.exe => moved successfully.
C:\zoek-results2015-07-05-104237.log => moved successfully.
C:\Windows\setupact.log => moved successfully.
C:\Windows\setuperr.log => moved successfully.
C:\zoek-results.log => moved successfully.
C:\zoek_backup => moved successfully.
C:\Users\okadmin\Downloads\zoek.exe => moved successfully.
C:\AdwCleaner => moved successfully.
C:\Users\okadmin\Desktop\adwcleaner_4.207.exe => moved successfully.
C:\rsit => moved successfully.
C:\Program Files\trend micro => moved successfully.
C:\Users\okadmin\Downloads\RSITx64.exe => moved successfully.
C:\Users\okadmin\Downloads\ccsetup507pro.exe => moved successfully.
C:\ProgramData\hpzinstall.log => moved successfully.
C:\ProgramData\{051B9612-4D82-42AC-8C63-CD2DCEDC1CB3}.log => moved successfully.
C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log => moved successfully.
C:\ProgramData\{23F3DA62-2D9E-4A69-B8D5-BE8E9E148092}.log => moved successfully.
C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log => moved successfully.
C:\ProgramData\{4FC670EB-5F02-4B07-90DB-022B86BFEFD0}.log => moved successfully.
C:\ProgramData\{9867824A-C86D-4A83-8F3C-E7A86BE0AFD3}.log => moved successfully.
C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log => moved successfully.
C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log => moved successfully.
C:\ProgramData\{d36dd326-7280-11d8-97c8-000129760cbe}.log => moved successfully.
C:\Windows\Tasks\Adobe Flash Player Updater.job => moved successfully.
C:\Windows\Tasks\HPCeeScheduleForokadmin.job => moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{04D96C0A-305A-4C91-9C96-A98B3ED69639}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04D96C0A-305A-4C91-9C96-A98B3ED69639}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv 2-codedownloader" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4528444E-49CD-43FA-869F-0B1E5A349C02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4528444E-49CD-43FA-869F-0B1E5A349C02}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avastBCLRestartS-1-5-21-1641521609-2111440031-3658305165-1000" => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite => key removed successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent => key removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully.
Hosts restored successfully.
EmptyTemp: => 74.1 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 02:44:04 ====

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 18 črc 2015 05:13
od vyosek
Jak se chova PC??

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 18 črc 2015 11:21
od Taras
Mnohem lépe! Zatím, kdyby něco bylo špatně tak se ozvu, ale prozatím vám mockrá děkuji :) Podpořim forum :)

Re: Prosím pommoc, počítač napadený, RSIT log

Napsal: 20 črc 2015 15:58
od vyosek
Tak jeste uklidime :James008:

:arrow: DelFix https://toolslib.net/downloads/finish/2/
  • Stahnete a spustte
  • Ponechte zatrzitkou pouze u volby Remove disinfection tools
  • Kliknete na Run
:arrow: Stahnete Ccleaner https://www.piriform.com/ccleaner/download/standard
Panel čistič
  • Vse nechte jak je, jen dejte Analyzovat a pote Spustit CCleaner
Panel registry
  • dejte Hledej problémy
  • nasledne Opravit problémy - zalohu registru doporucuji udelat, opravte vsechny problemy
  • postup opakujte dokud nebude bez problemu - vetsinou cca 3x
Panel nástroje
  • Zde muzete odinstalovat nepotrebne programy
CCleaner doporucuji pouzivat cca jednou za tyden

:arrow: A pokud nejsou problemy ci dotazy, je to z me strany vse :|