Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

adware-gen, evo-gen, v chrome mystartsearch

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

adware-gen, evo-gen, v chrome mystartsearch

#1 Příspěvek od mandra »

Dobrý den,

avast pořád nachází adware-gen a evo-gen, chrome zase vždy po restartu otvírá stránku mystartsearch. Několikrát jsem to mazala a pořád se to vrací, proto prosím o pomoc.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:16-10-2015
Ran by Helca (administrator) on HELCA-PC (17-10-2015 11:18:48)
Running from C:\Users\Helca\Desktop
Loaded Profiles: Helca (Available Profiles: Helca & benjamin sufner)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser not detected!)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AdminService.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\AsHookDevice.exe
(DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5\knsm4257.tmpfs
() C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5\hnssA4E9.tmp
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
() C:\Users\Helca\AppData\Local\25D8A476-7542-4272-A54B-332C1645FFD\25D8A476-7542-4272-A54B-332C1645FFD.exe
(Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ExpressGateBIOSSwitch] => C:\ASUS.SYS\config\EGSwitch.exe [618600 2010-05-10] (DeviceVM, Inc.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8546848 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-29] (AVAST Software)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [461984 2010-05-05] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] => C:\Program Files\Bluetooth Suite\AthBtTray.exe [289952 2010-05-05] (Atheros Commnucations)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-07-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-29] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{A67352D4-DA63-43D9-AE77-BD648DBC35D3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{E9DFA3C0-99DE-4E02-B2D6-C9354C3BEB57}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-05] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-05] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-05] (Oracle Corporation)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=14434 ... J90B209622

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-05] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-29] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-29] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-06-04]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://www.google.cz/ ... kid=sp-006"
CHR DefaultSearchURL: Default -> hxxps://www.google.de/search?q={searchTerms}&trackid=sp-006
CHR DefaultSuggestURL: Default -> hxxps://www.google.com/complete/search?client=c ... earchTerms}
CHR Profile: C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-04]
CHR Extension: (Beautiful landscape) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ambfimhigppdidfmelpjmojccbfdoeig [2015-10-02]
CHR Extension: (Dokumenty Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-04]
CHR Extension: (Disk Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-04]
CHR Extension: (MyNetDiary Calorie Counter and Food Diary) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjackipnjjjefeppmpbgcdefaplneopj [2015-06-04]
CHR Extension: (YouTube) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-04]
CHR Extension: (Math Mahjong) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbcfbhpnngegochhbdlanodnmijfplal [2015-06-04]
CHR Extension: (Vyhledávání Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-04]
CHR Extension: (GAIN Fitness) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpompjlmddcnpijabjfcgnpmoibdffoc [2015-06-04]
CHR Extension: (Solitairey) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp [2015-06-04]
CHR Extension: (Mahjongg) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2015-06-04]
CHR Extension: (Tabulky Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-10]
CHR Extension: (Avast Online Security) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-09-28]
CHR Extension: (World of Solitaire) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2015-06-04]
CHR Extension: (Lose It!) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jehemifhdilebjjpibeianiedocpgocn [2015-06-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-04]
CHR Extension: (TypingClub) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\obdbgibnhfcjmmpfijkpcihjieedpfah [2015-06-04]
CHR Extension: (Avast Antivirus 2015) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehdbifhljldbcdjbendhjmjjbfbdejp [2015-09-28]
CHR Extension: (Gmail) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-04]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-06-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-04]
StartMenuInternet: Google Chrome - C:\Program Files\Google\Chrome\Application\chrome.exe hxxp://www.mystartsearch.com/?type=sc&ts=14449 ... J90B209622

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [38560 2010-05-05] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-29] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-10-14] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3219136 2015-09-29] (Avast Software)
R2 Device Handle Service; C:\Windows\system32\AsHookDevice.exe [203392 2009-12-23] (ASUSTeK Computer Inc.)
R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-10-16] (DeviceVM, Inc.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [921232 2015-07-14] (NVIDIA Corporation)
R2 gyvixodu; C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5\hnssA4E9.tmp [203776 2015-09-28] () [File not signed]
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4304528 2015-07-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2078216 2015-09-25] (Electronic Arts)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
R2 gigoxydi; C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5\knsm4257.tmpfs [X]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASInsHelp; C:\Windows\system32\drivers\AsInsHelp32.sys [10216 2008-01-04] ()
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11448 2009-07-06] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-09-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-10-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-09-29] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [275856 2015-10-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-09-29] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-09-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [789296 2015-09-29] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [434184 2015-09-29] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [115640 2015-09-29] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-09-29] (AVAST Software)
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [38440 2010-03-30] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-03-30] (Windows (R) Win 7 DDK provider)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3335168 2015-03-05] (Qualcomm Atheros Communications, Inc.)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [256360 2010-04-18] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28200 2010-03-30] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [177704 2010-03-30] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [46952 2010-04-13] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143080 2010-04-18] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [230760 2010-04-21] (Atheros)
R1 DVMIO; C:\Windows\System32\DRIVERS\dvmio.sys [18136 2010-05-07] (DeviceVM, Inc.)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [14848 2010-06-19] (Siliten)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [107984 2015-09-29] (AVAST Software)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [73984 2011-10-25] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [165120 2011-10-25] (Renesas Electronics Corporation)
S3 nuviocir; C:\Windows\System32\DRIVERS\nuviocir_win7_x86.sys [29696 2009-06-19] (Nuvoton Technology Corp.) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-07-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [42344 2015-07-03] (NVIDIA Corporation)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [33056 2010-01-14] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2010-01-14] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [25376 2010-01-14] (Windows (R) Codename Longhorn DDK provider)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2010-01-14] (Realtek Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-09-29] (Avast Software)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-17 11:18 - 2015-10-17 11:19 - 00017716 _____ C:\Users\Helca\Desktop\FRST.txt
2015-10-17 11:18 - 2015-10-17 11:18 - 00000000 ____D C:\FRST
2015-10-17 11:08 - 2015-10-17 11:10 - 01700352 _____ (Farbar) C:\Users\Helca\Desktop\FRST.exe
2015-10-17 09:25 - 2015-10-17 09:27 - 00002042 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-16 01:33 - 2015-10-16 01:33 - 00000000 ____D C:\Users\Helca\AppData\Local\25D8A476-7542-4272-A54B-332C1645FFD
2015-10-16 01:00 - 2015-10-17 09:21 - 00002974 _____ C:\Windows\PFRO.log
2015-10-16 00:54 - 2015-10-16 00:54 - 00000000 ____D C:\ProgramData\4WdsManPro4
2015-10-16 00:34 - 2015-09-18 19:47 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-10-16 00:34 - 2015-09-18 19:44 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-10-16 00:34 - 2015-09-18 19:35 - 00999936 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-10-16 00:33 - 2015-10-16 00:33 - 00000000 ____D C:\Users\benjamin sufner\AppData\Local\Crossbrowse
2015-10-16 00:30 - 2015-10-16 00:30 - 00008900 _____ C:\Windows\DPINST.LOG
2015-10-15 07:55 - 2015-09-25 19:59 - 02955776 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-10-15 07:55 - 2015-09-25 19:58 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-10-15 07:55 - 2015-09-25 19:58 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-10-15 07:55 - 2015-09-25 19:58 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-10-15 07:55 - 2015-09-25 19:58 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-10-14 19:11 - 2015-09-18 20:58 - 00345688 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-10-14 19:11 - 2015-09-16 05:58 - 20357632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-10-14 19:11 - 2015-09-16 05:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-10-14 19:11 - 2015-09-16 05:45 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-10-14 19:11 - 2015-09-16 05:33 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-10-14 19:11 - 2015-09-16 05:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-10-14 19:11 - 2015-09-16 05:32 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-10-14 19:11 - 2015-09-16 05:32 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-10-14 19:11 - 2015-09-16 05:31 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-10-14 19:11 - 2015-09-16 05:28 - 02279936 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-10-14 19:11 - 2015-09-16 05:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-10-14 19:11 - 2015-09-16 05:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-10-14 19:11 - 2015-09-16 05:24 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-10-14 19:11 - 2015-09-16 05:23 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-10-14 19:11 - 2015-09-16 05:23 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-10-14 19:11 - 2015-09-16 05:22 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-10-14 19:11 - 2015-09-16 05:22 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-10-14 19:11 - 2015-09-16 05:18 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-10-14 19:11 - 2015-09-16 05:15 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-10-14 19:11 - 2015-09-16 05:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 19:11 - 2015-09-16 05:07 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-10-14 19:11 - 2015-09-16 05:06 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-10-14 19:11 - 2015-09-16 05:05 - 04527616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-10-14 19:11 - 2015-09-16 05:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-10-14 19:11 - 2015-09-16 05:04 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-10-14 19:11 - 2015-09-16 04:58 - 12853760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-10-14 19:11 - 2015-09-16 04:58 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-10-14 19:11 - 2015-09-16 04:56 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-10-14 19:11 - 2015-09-16 04:56 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-10-14 19:11 - 2015-09-16 04:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-10-14 19:11 - 2015-09-16 04:55 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-10-14 19:11 - 2015-09-16 04:37 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-10-14 19:11 - 2015-09-16 04:34 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-10-14 19:11 - 2015-09-16 04:32 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-10-14 17:58 - 2015-10-17 10:55 - 00001120 _____ C:\Windows\setupact.log
2015-10-14 17:58 - 2015-10-14 17:58 - 00000000 _____ C:\Windows\setuperr.log
2015-10-14 17:51 - 2015-10-14 17:52 - 00000000 ____D C:\ProgramData\eWdsManProe
2015-10-14 17:17 - 2015-10-01 19:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 17:17 - 2015-10-01 19:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 17:17 - 2015-10-01 18:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-10-14 17:03 - 2015-10-14 17:03 - 00002063 _____ C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-10-14 17:03 - 2015-10-14 17:03 - 00002003 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-10-14 17:03 - 2015-10-14 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-14 17:01 - 2015-10-14 17:01 - 00026096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2015-10-14 17:01 - 2015-09-29 18:22 - 00313472 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-10-14 17:01 - 2015-09-29 05:05 - 03990976 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-10-14 17:01 - 2015-09-29 05:05 - 03936192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-10-14 17:01 - 2015-09-29 05:02 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-10-14 17:01 - 2015-09-29 04:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-10-14 17:01 - 2015-09-29 04:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-10-14 17:01 - 2015-09-29 04:49 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-10-14 17:01 - 2015-09-29 04:49 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-10-14 17:01 - 2015-09-29 03:43 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-10-14 17:01 - 2015-09-29 03:43 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-10-14 17:01 - 2015-09-29 03:43 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-10-14 17:01 - 2015-09-15 19:42 - 00139096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-10-14 17:01 - 2015-09-15 19:42 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-10-14 17:01 - 2015-09-15 19:36 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-10-14 17:01 - 2015-09-15 19:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-10-14 17:01 - 2015-07-18 15:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-14 17:00 - 2015-10-14 17:00 - 00275856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-10-14 16:31 - 2015-08-06 19:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 16:31 - 2015-08-06 19:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-10-14 16:15 - 2015-10-14 16:16 - 00000000 ____D C:\ProgramData\1WdsManPro1
2015-10-14 16:15 - 2015-10-14 16:15 - 00000000 ____D C:\Users\Helca\AppData\Roaming\mystartsearch
2015-10-13 17:18 - 2015-10-13 17:19 - 00000000 ____D C:\ProgramData\tWdsManProt
2015-10-12 00:06 - 2015-10-12 00:06 - 00000000 ____D C:\Users\benjamin sufner\AppData\Local\MyBrowser
2015-10-11 23:10 - 2015-10-12 16:19 - 00000000 ____D C:\Users\Helca\AppData\Roaming\systweak
2015-10-11 23:10 - 2015-07-02 14:14 - 00018200 _____ () C:\Windows\system32\roboot.exe
2015-10-11 23:05 - 2015-10-11 23:06 - 00000000 ____D C:\ProgramData\vWdsManProv
2015-10-08 14:04 - 2015-10-08 14:05 - 00000000 ____D C:\ProgramData\UWdsManProU
2015-10-07 16:32 - 2015-10-07 16:33 - 00000000 ____D C:\ProgramData\9WdsManPro9
2015-10-06 17:28 - 2015-10-06 17:28 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsnE25.tmp
2015-10-06 17:27 - 2015-10-14 18:35 - 00001184 _____ C:\task.vbs
2015-10-05 19:27 - 2015-10-05 19:27 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiC321.tmp
2015-10-05 19:25 - 2015-10-05 19:25 - 00000000 ____D C:\Program Files\Feed Notifier
2015-10-04 10:28 - 2015-10-04 10:28 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nssF748.tmp
2015-10-03 19:22 - 2015-10-03 19:22 - 00001724 _____ C:\Users\Helca\Desktop\Play SimCity 2013 Offline.lnk
2015-10-03 19:16 - 2015-10-03 19:22 - 00000000 ____D C:\Games
2015-10-03 17:44 - 2015-10-03 19:24 - 00000000 ____D C:\Users\Helca\AppData\Roaming\uTorrent
2015-10-03 17:32 - 2015-10-03 17:32 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsd450.tmp
2015-10-03 12:32 - 2015-10-03 12:32 - 00000000 ____D C:\Users\Helca\Documents\SimCity
2015-10-03 12:07 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-10-03 12:07 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-10-03 12:07 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-10-03 12:07 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-10-03 12:07 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-10-03 12:07 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-10-03 12:07 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-10-03 12:07 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-10-03 12:07 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-10-03 12:07 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-10-03 12:07 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-10-03 12:07 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-10-03 12:07 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-10-03 12:07 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-10-03 12:07 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-10-03 12:07 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-10-03 12:07 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-10-03 12:07 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-10-03 12:07 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-10-03 12:07 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-10-03 12:07 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-10-03 12:07 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-10-03 11:43 - 2015-10-07 19:55 - 00000364 _____ C:\Windows\Tasks\APSnotifierPP2.job
2015-10-03 11:43 - 2015-10-07 15:59 - 00000364 _____ C:\Windows\Tasks\APSnotifierPP3.job
2015-10-03 11:42 - 2015-10-06 17:52 - 00000366 _____ C:\Windows\Tasks\APSnotifierPP1.job
2015-10-03 11:40 - 2015-10-03 11:40 - 00000000 ____D C:\Windows\system32\Flash
2015-10-03 11:37 - 2015-10-03 11:37 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsu35BB.tmp
2015-10-02 14:04 - 2015-10-02 14:28 - 00000000 ____D C:\ProgramData\8WdsManPro8
2015-10-02 14:04 - 2015-10-02 14:04 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsn4DFF.tmp
2015-09-29 18:46 - 2015-09-29 18:01 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiBFE3.tmp
2015-09-29 18:22 - 2015-09-29 18:22 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-09-29 18:06 - 2015-09-29 18:06 - 00001092 _____ C:\Users\Helca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-29 18:06 - 2015-09-29 18:06 - 00001092 _____ C:\Users\benjamin sufner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-29 18:01 - 2015-09-29 18:02 - 00000000 ____D C:\ProgramData\FWdsManProF
2015-09-28 13:05 - 2015-09-28 13:06 - 00000000 ____D C:\ProgramData\XWdsManProX
2015-09-28 12:47 - 2015-10-14 19:28 - 00000000 ____D C:\Users\Helca\AppData\Roaming\Seznam.cz
2015-09-28 12:47 - 2015-10-14 19:26 - 00000000 ____D C:\Program Files\Seznam.cz
2015-09-28 12:44 - 2015-09-28 12:44 - 00000000 __SHD C:\Users\Helca\AppData\Roaming\AnyProtectEx
2015-09-28 12:43 - 2015-10-16 00:54 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-09-28 12:43 - 2015-09-28 12:44 - 00000000 ____D C:\ProgramData\iWdsManProi
2015-09-28 12:36 - 2015-09-28 12:37 - 00000000 ____D C:\Users\Helca\AppData\Roaming\Opera Software
2015-09-28 12:36 - 2015-09-28 12:37 - 00000000 ____D C:\Users\Helca\AppData\Local\Opera Software
2015-09-28 12:34 - 2015-09-28 12:37 - 00000000 ____D C:\Program Files\Opera
2015-09-28 12:33 - 2015-09-28 12:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-09-28 12:32 - 2015-10-09 18:01 - 00000000 ____D C:\Users\Helca\AppData\Roaming\VOPackage
2015-09-28 12:32 - 2015-10-02 14:21 - 00000000 ____D C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5
2015-09-28 12:32 - 2015-09-29 17:30 - 00000000 ____D C:\Users\Helca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-09-28 12:32 - 2015-09-28 12:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-28 12:32 - 2009-06-10 23:39 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-09-27 14:25 - 2015-09-27 14:25 - 00000000 ____D C:\.oracle_jre_usage
2015-09-25 13:52 - 2015-09-25 13:52 - 00001296 _____ C:\Users\Public\Desktop\The Sims 4.lnk
2015-09-25 13:52 - 2015-09-25 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
2015-09-23 06:50 - 2015-10-03 18:43 - 00000000 ____D C:\Users\Helca\Desktop\Mods
2015-09-22 11:35 - 2015-05-06 17:07 - 00295906 _____ C:\Users\Helca\Desktop\BeachBackground_Annett85 (5).package
2015-09-22 11:28 - 2015-09-22 11:29 - 00000000 ____D C:\Users\benjamin sufner\Desktop\Mods
2015-09-21 15:25 - 2015-09-21 15:00 - 00381913 _____ C:\Users\Helca\Desktop\BeachBackground_Annett85 (2).package
2015-09-21 15:17 - 2015-09-21 15:18 - 351470129 _____ C:\Users\Helca\Desktop\stažené soubory.zip
2015-09-21 15:17 - 2015-09-21 15:17 - 00000000 ____D C:\Users\Helca\Desktop\stažené soubory
2015-09-21 14:59 - 2015-06-14 17:05 - 00298848 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau3.package
2015-09-21 14:59 - 2015-06-14 16:48 - 00284483 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau2.package
2015-09-21 14:59 - 2015-06-14 16:36 - 00300097 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau1.package
2015-09-21 14:59 - 2015-05-13 15:20 - 00000584 _____ C:\Users\benjamin sufner\Desktop\Credits.txt
2015-09-21 14:58 - 2015-05-06 17:07 - 00295906 _____ C:\Users\benjamin sufner\Desktop\BeachBackground_Annett85 (5).package
2015-09-21 14:56 - 2015-09-21 14:56 - 00000000 ____D C:\Users\benjamin sufner\AppData\Local\CrashDumps

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-17 11:14 - 2015-06-03 17:43 - 01548830 _____ C:\Windows\WindowsUpdate.log
2015-10-17 11:05 - 2015-06-03 18:52 - 00000177 ____H C:\dvmexp.idx
2015-10-17 11:04 - 2009-07-14 06:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-17 11:04 - 2009-07-14 06:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-17 10:59 - 2015-06-03 18:23 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-17 10:57 - 2015-09-01 00:11 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e43a86c6dc6.job
2015-10-17 10:57 - 2015-06-04 18:53 - 00000043 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2015-10-17 10:55 - 2015-06-09 18:49 - 00000000 ____D C:\ProgramData\NVIDIA
2015-10-17 10:55 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-17 09:27 - 2015-06-09 03:22 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-10-17 09:27 - 2015-06-09 03:22 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-17 09:25 - 2015-06-04 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-17 09:22 - 2015-09-01 00:11 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e43a941c0ec.job
2015-10-16 00:30 - 2015-07-29 16:58 - 00001972 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2015-10-16 00:30 - 2015-07-29 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-10-16 00:29 - 2015-06-03 18:29 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-10-15 07:59 - 2015-06-14 13:53 - 00000000 ____D C:\Windows\system32\MRT
2015-10-15 07:42 - 2015-06-14 13:52 - 141105520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-10-14 17:58 - 2015-06-03 18:26 - 00000000 ____D C:\Users\Helca
2015-10-14 17:31 - 2015-08-17 09:13 - 00000000 ____D C:\Users\Helca\AppData\Local\CrashDumps
2015-10-13 16:39 - 2015-08-16 20:35 - 00000000 ____D C:\ProgramData\Origin
2015-10-09 14:37 - 2015-08-17 04:15 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-03 17:48 - 2015-08-16 20:39 - 00000000 ____D C:\Program Files\Origin Games
2015-10-03 17:48 - 2009-07-14 06:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-29 18:22 - 2015-06-04 18:32 - 00434184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00208664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00115640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00081728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00076000 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-09-29 18:21 - 2015-09-05 17:25 - 00107984 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys
2015-09-29 18:21 - 2015-06-04 18:32 - 00789296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-09-25 17:19 - 2015-08-16 20:34 - 00000000 ____D C:\Program Files\Origin
2015-09-25 16:56 - 2015-08-16 20:34 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-09-22 12:32 - 2015-06-09 19:33 - 00000000 ____D C:\Program Files\Minecraft
2015-09-21 15:49 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles
2015-09-20 20:02 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-18 07:07 - 2015-06-04 17:54 - 00000000 ____D C:\Users\Helca\AppData\Local\Google

==================== Files in the root of some directories =======

2015-10-03 17:32 - 2015-10-03 17:32 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsd450.tmp
2015-09-29 18:46 - 2015-09-29 18:01 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiBFE3.tmp
2015-10-05 19:27 - 2015-10-05 19:27 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiC321.tmp
2015-10-02 14:04 - 2015-10-02 14:04 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsn4DFF.tmp
2015-10-06 17:28 - 2015-10-06 17:28 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsnE25.tmp
2015-10-04 10:28 - 2015-10-04 10:28 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nssF748.tmp
2015-10-03 11:37 - 2015-10-03 11:37 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsu35BB.tmp
2015-09-28 12:43 - 2015-10-16 00:54 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Some files in TEMP:
====================
C:\Users\Helca\AppData\Local\Temp\3353.exe
C:\Users\Helca\AppData\Local\Temp\5847.exe
C:\Users\Helca\AppData\Local\Temp\7672.exe
C:\Users\Helca\AppData\Local\Temp\8103.exe
C:\Users\Helca\AppData\Local\Temp\9265.exe
C:\Users\Helca\AppData\Local\Temp\fsd39B5.exe
C:\Users\Helca\AppData\Local\Temp\fsd8C97.exe
C:\Users\Helca\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-11 23:25

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: adware-gen, evo-gen, v chrome mystartsearch

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

Re: adware-gen, evo-gen, v chrome mystartsearch

#3 Příspěvek od mandra »

hotovo...tady je log

# AdwCleaner v5.013 - Logfile created 17/10/2015 at 12:32:59
# Updated 09/10/2015 by Xplode
# Database : 2015-10-16.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Helca - HELCA-PC
# Running from : C:\Users\Helca\Desktop\adwcleaner_5.013.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : gigoxydi
[-] Service Deleted : gyvixodu

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files\Feed Notifier
[-] Folder Deleted : C:\Program Files\1E00D220-1443436325-3900-4819-20CF30C7C7F5
[-] Folder Deleted : C:\ProgramData\Trymedia
[-] Folder Deleted : C:\ProgramData\1WdsManPro1
[-] Folder Deleted : C:\ProgramData\4WdsManPro4
[-] Folder Deleted : C:\ProgramData\8WdsManPro8
[-] Folder Deleted : C:\ProgramData\9WdsManPro9
[-] Folder Deleted : C:\ProgramData\eWdsManProe
[-] Folder Deleted : C:\ProgramData\FWdsManProF
[-] Folder Deleted : C:\ProgramData\iWdsManProi
[-] Folder Deleted : C:\ProgramData\tWdsManProt
[-] Folder Deleted : C:\ProgramData\UWdsManProU
[-] Folder Deleted : C:\ProgramData\vWdsManProv
[-] Folder Deleted : C:\ProgramData\XWdsManProX
[-] Folder Deleted : C:\Users\benjamin sufner\AppData\Local\Crossbrowse
[-] Folder Deleted : C:\Users\Helca\AppData\Roaming\AnyProtectEx
[-] Folder Deleted : C:\Users\Helca\AppData\Roaming\Systweak
[-] Folder Deleted : C:\Users\Helca\AppData\Roaming\VOPackage
[-] Folder Deleted : C:\Users\Helca\AppData\Roaming\mystartsearch
[-] Folder Deleted : C:\Users\Helca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage

***** [ Files ] *****

[-] File Deleted : C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
[-] File Deleted : C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal
[-] File Deleted : C:\Windows\system32\roboot.exe

***** [ DLLs ] *****


***** [ Shortcuts ] *****

[-] Shortcut Disinfected : C:\Users\Helca\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

***** [ Scheduled tasks ] *****

[-] Task Deleted : APSnotifierPP1
[-] Task Deleted : APSnotifierPP2
[-] Task Deleted : APSnotifierPP3

***** [ Registry ] *****

[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
[-] Key Deleted : HKCU\Software\AnyProtect
[-] Key Deleted : HKCU\Software\systweak
[-] Key Deleted : HKCU\Software\CrossBrowser
[-] Key Deleted : HKCU\Software\Crossbrowse
[-] Key Deleted : HKCU\Software\OB
[-] Key Deleted : HKLM\SOFTWARE\systweak
[-] Key Deleted : HKLM\SOFTWARE\mystartsearchSoftware
[-] Key Deleted : HKLM\SOFTWARE\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\WdsManPro
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99AD9D6D-A456-49EE-8360-F22EE7AA1272}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
[-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command []
[-] Data Restored : HKLM\SOFTWARE\Clients\StartMenuInternet\Google Chrome\shell\open\command []

***** [ Web browsers ] *****

[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mpc
[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : myplaycity.com
[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystartsearch.com
[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystartsearch
[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.mystartsearch.com/?type=hp&ts=14449 ... J90B209622
[-] [C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Deleted : hxxp://www.mystartsearch.com/webfavicon.ico

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [4276 bytes] ##########

mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

Re: adware-gen, evo-gen, v chrome mystartsearch

#4 Příspěvek od mandra »

ještě jedna věc....teď se mi po restartu nainstaloval prohlížeč MyBrowser a tváří se jako Chrome :shock:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: adware-gen, evo-gen, v chrome mystartsearch

#5 Příspěvek od Rudy »

Za to ale ADW nemůže. Dejte nový log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

Re: adware-gen, evo-gen, v chrome mystartsearch

#6 Příspěvek od mandra »

Já vím, že to nebylo tím AC, ale nějakým neřádem, co ho mám v PC.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-10-2015
Ran by Helca (administrator) on HELCA-PC (17-10-2015 17:38:53)
Running from C:\Users\Helca\Desktop
Loaded Profiles: Helca (Available Profiles: Helca & benjamin sufner)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: "C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe" -- "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AdminService.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\AsHookDevice.exe
(DeviceVM, Inc.) C:\ASUS.SYS\config\DVMExportService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Renesas Electronics Corporation) C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files\Bluetooth Suite\AthBtTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Sony) C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Program Files\Sony\Sony PC Companion\PCCompanionInfo.exe
(Electronic Arts) C:\Program Files\Origin\Origin.exe
(MyBrowser) C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe
(MyBrowser) C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe
(Electronic Arts Inc.) C:\Program Files\Origin Games\The Sims 4\Game\Bin\TS4.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ExpressGateBIOSSwitch] => C:\ASUS.SYS\config\EGSwitch.exe [618600 2010-05-10] (DeviceVM, Inc.)
HKLM\...\Run: [NUSB3MON] => C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [115048 2011-09-16] (Renesas Electronics Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8546848 2010-03-17] (Realtek Semiconductor)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-29] (AVAST Software)
HKLM\...\Run: [AtherosBtStack] => C:\Program Files\Bluetooth Suite\BtvStack.exe [461984 2010-05-05] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] => C:\Program Files\Bluetooth Suite\AthBtTray.exe [289952 2010-05-05] (Atheros Commnucations)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Run: [Sony PC Companion] => C:\Program Files\Sony\Sony PC Companion\PCCompanion.exe [457088 2015-09-23] (Sony)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Run: [GoogleChromeAutoLaunch_86C0A2F254862841B3FCDAAA457F4271] => C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe [636928 2015-08-29] (MyBrowser)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2015-07-11] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-09-29] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{A67352D4-DA63-43D9-AE77-BD648DBC35D3}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{E9DFA3C0-99DE-4E02-B2D6-C9354C3BEB57}: [DhcpNameServer] 192.168.1.1 192.168.1.1

Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-09-05] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-05] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-09-05] (Oracle Corporation)

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-09-05] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-09-05] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-29] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-29] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-18] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-06-04] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://www.google.cz/ ... kid=sp-006"
CHR DefaultSearchURL: Default -> hxxp://www.mystartsearch.com/web/?type=ds&ts=1 ... earchTerms}
CHR DefaultSearchKeyword: Default -> mystartsearch
CHR Profile: C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-04]
CHR Extension: (Beautiful landscape) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ambfimhigppdidfmelpjmojccbfdoeig [2015-10-02]
CHR Extension: (Dokumenty Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-04]
CHR Extension: (Disk Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-04]
CHR Extension: (MyNetDiary Calorie Counter and Food Diary) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjackipnjjjefeppmpbgcdefaplneopj [2015-06-04]
CHR Extension: (YouTube) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-04]
CHR Extension: (Math Mahjong) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbcfbhpnngegochhbdlanodnmijfplal [2015-06-04]
CHR Extension: (Vyhledávání Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-04]
CHR Extension: (GAIN Fitness) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpompjlmddcnpijabjfcgnpmoibdffoc [2015-06-04]
CHR Extension: (Solitairey) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp [2015-06-04]
CHR Extension: (Mahjongg) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2015-06-04]
CHR Extension: (Tabulky Google) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-04]
CHR Extension: (Dokumenty Google offline) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-10]
CHR Extension: (Avast Online Security) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-09-28]
CHR Extension: (World of Solitaire) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn [2015-06-04]
CHR Extension: (Lose It!) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\jehemifhdilebjjpibeianiedocpgocn [2015-06-04]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-04]
CHR Extension: (TypingClub) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\obdbgibnhfcjmmpfijkpcihjieedpfah [2015-06-04]
CHR Extension: (Avast Antivirus 2015) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehdbifhljldbcdjbendhjmjjbfbdejp [2015-09-28]
CHR Extension: (Gmail) - C:\Users\Helca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-04]
CHR HKLM\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-06-04]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-04]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\Program Files\Bluetooth Suite\adminservice.exe [38560 2010-05-05] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-29] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-10-14] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [3219136 2015-09-29] (Avast Software)
R2 Device Handle Service; C:\Windows\system32\AsHookDevice.exe [203392 2009-12-23] (ASUSTeK Computer Inc.)
R2 DvmMDES; C:\ASUS.SYS\config\DVMExportService.exe [319488 2009-10-16] (DeviceVM, Inc.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [921232 2015-07-14] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-14] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4304528 2015-07-14] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files\Origin\OriginClientService.exe [2078216 2015-09-25] (Electronic Arts)
S3 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155520 2015-06-10] (Avanquest Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ASInsHelp; C:\Windows\system32\drivers\AsInsHelp32.sys [10216 2008-01-04] ()
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [11296 2009-08-04] ()
R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11448 2009-07-06] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-09-29] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [26096 2015-10-14] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [76000 2015-09-29] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [275856 2015-10-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81728 2015-09-29] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-09-29] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [789296 2015-09-29] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [434184 2015-09-29] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [115640 2015-09-29] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [208664 2015-09-29] (AVAST Software)
S3 AthBTPort; C:\Windows\System32\DRIVERS\btath_flt.sys [38440 2010-03-30] (Atheros)
S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [47144 2010-03-30] (Windows (R) Win 7 DDK provider)
R3 athr; C:\Windows\System32\DRIVERS\athr.sys [3335168 2015-03-05] (Qualcomm Atheros Communications, Inc.)
S3 BTATH_A2DP; C:\Windows\System32\drivers\btath_a2dp.sys [256360 2010-04-18] (Atheros)
R3 BTATH_BUS; C:\Windows\System32\DRIVERS\btath_bus.sys [28200 2010-03-30] (Atheros)
S3 BTATH_HCRP; C:\Windows\System32\DRIVERS\btath_hcrp.sys [177704 2010-03-30] (Atheros)
S3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [46952 2010-04-13] (Atheros)
S3 BTATH_RCP; C:\Windows\System32\DRIVERS\btath_rcp.sys [143080 2010-04-18] (Atheros)
S3 BtFilter; C:\Windows\System32\DRIVERS\btfilter.sys [230760 2010-04-21] (Atheros)
R1 DVMIO; C:\Windows\System32\DRIVERS\dvmio.sys [18136 2010-05-07] (DeviceVM, Inc.)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [14848 2010-06-19] (Siliten)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2009-07-16] ()
R0 ngvss; C:\Windows\system32\Drivers\ngvss.sys [107984 2015-09-29] (AVAST Software)
R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [73984 2011-10-25] (Renesas Electronics Corporation)
R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [165120 2011-10-25] (Renesas Electronics Corporation)
S3 nuviocir; C:\Windows\System32\DRIVERS\nuviocir_win7_x86.sys [29696 2009-06-19] (Nuvoton Technology Corp.) [File not signed]
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-07-14] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [42344 2015-07-03] (NVIDIA Corporation)
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [33056 2010-01-14] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2010-01-14] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [25376 2010-01-14] (Windows (R) Codename Longhorn DDK provider)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [40736 2010-01-14] (Realtek Corporation)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [220752 2015-09-29] (Avast Software)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-17 17:38 - 2015-10-17 17:38 - 00000000 ____D C:\Users\Helca\Desktop\FRST-OlderVersion
2015-10-17 12:46 - 2015-10-17 12:46 - 00002286 _____ C:\Users\Public\Desktop\MyBrowser.lnk
2015-10-17 12:46 - 2015-10-17 12:46 - 00001036 _____ C:\Windows\Tasks\MyBrowser.job
2015-10-17 12:46 - 2015-10-17 12:46 - 00000000 ____D C:\Users\Helca\AppData\Local\MyBrowser
2015-10-17 12:46 - 2015-10-17 12:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyBrowser
2015-10-17 12:45 - 2015-10-17 12:45 - 00000000 ____D C:\Program Files\MyBrowser
2015-10-17 12:24 - 2015-10-17 12:27 - 01682432 _____ C:\Users\Helca\Desktop\adwcleaner_5.013.exe
2015-10-17 11:20 - 2015-10-17 11:21 - 00027566 _____ C:\Users\Helca\Desktop\Addition.txt
2015-10-17 11:18 - 2015-10-17 17:40 - 00017458 _____ C:\Users\Helca\Desktop\FRST.txt
2015-10-17 11:18 - 2015-10-17 17:39 - 00000000 ____D C:\FRST
2015-10-17 11:08 - 2015-10-17 17:38 - 01700864 _____ (Farbar) C:\Users\Helca\Desktop\FRST.exe
2015-10-17 09:25 - 2015-10-17 09:27 - 00002042 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-16 01:33 - 2015-10-16 01:33 - 00000000 ____D C:\Users\Helca\AppData\Local\25D8A476-7542-4272-A54B-332C1645FFD
2015-10-16 01:00 - 2015-10-17 09:21 - 00002974 _____ C:\Windows\PFRO.log
2015-10-16 00:34 - 2015-09-18 19:47 - 00023384 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-10-16 00:34 - 2015-09-18 19:44 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-10-16 00:34 - 2015-09-18 19:44 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-10-16 00:34 - 2015-09-18 19:35 - 00999936 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-10-16 00:30 - 2015-10-16 00:30 - 00008900 _____ C:\Windows\DPINST.LOG
2015-10-15 07:55 - 2015-09-25 19:59 - 02955776 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 02061824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-10-15 07:55 - 2015-09-25 19:59 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-10-15 07:55 - 2015-09-25 19:58 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-10-15 07:55 - 2015-09-25 19:58 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-10-15 07:55 - 2015-09-25 19:58 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-10-15 07:55 - 2015-09-25 19:58 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-10-14 19:11 - 2015-09-18 20:58 - 00345688 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-10-14 19:11 - 2015-09-16 05:58 - 20357632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-10-14 19:11 - 2015-09-16 05:45 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-10-14 19:11 - 2015-09-16 05:45 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-10-14 19:11 - 2015-09-16 05:33 - 00504832 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-10-14 19:11 - 2015-09-16 05:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-10-14 19:11 - 2015-09-16 05:32 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-10-14 19:11 - 2015-09-16 05:32 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-10-14 19:11 - 2015-09-16 05:31 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-10-14 19:11 - 2015-09-16 05:28 - 02279936 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-10-14 19:11 - 2015-09-16 05:26 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-10-14 19:11 - 2015-09-16 05:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-10-14 19:11 - 2015-09-16 05:24 - 00480256 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-10-14 19:11 - 2015-09-16 05:23 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-10-14 19:11 - 2015-09-16 05:23 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-10-14 19:11 - 2015-09-16 05:22 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-10-14 19:11 - 2015-09-16 05:22 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-10-14 19:11 - 2015-09-16 05:18 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-10-14 19:11 - 2015-09-16 05:15 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-10-14 19:11 - 2015-09-16 05:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-10-14 19:11 - 2015-09-16 05:07 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-10-14 19:11 - 2015-09-16 05:06 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-10-14 19:11 - 2015-09-16 05:05 - 04527616 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-10-14 19:11 - 2015-09-16 05:05 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-10-14 19:11 - 2015-09-16 05:04 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-10-14 19:11 - 2015-09-16 04:58 - 12853760 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-10-14 19:11 - 2015-09-16 04:58 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-10-14 19:11 - 2015-09-16 04:56 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-10-14 19:11 - 2015-09-16 04:56 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-10-14 19:11 - 2015-09-16 04:55 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-10-14 19:11 - 2015-09-16 04:55 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-10-14 19:11 - 2015-09-16 04:37 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-10-14 19:11 - 2015-09-16 04:34 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-10-14 19:11 - 2015-09-16 04:32 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-10-14 17:58 - 2015-10-17 12:35 - 00001288 _____ C:\Windows\setupact.log
2015-10-14 17:58 - 2015-10-14 17:58 - 00000000 _____ C:\Windows\setuperr.log
2015-10-14 17:17 - 2015-10-01 19:50 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-10-14 17:17 - 2015-10-01 19:50 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-10-14 17:17 - 2015-10-01 19:50 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-10-14 17:17 - 2015-10-01 18:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-10-14 17:03 - 2015-10-14 17:03 - 00002063 _____ C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-10-14 17:03 - 2015-10-14 17:03 - 00002003 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-10-14 17:03 - 2015-10-14 17:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-14 17:01 - 2015-10-14 17:01 - 00026096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2015-10-14 17:01 - 2015-09-29 18:22 - 00313472 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-10-14 17:01 - 2015-09-29 05:05 - 03990976 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-10-14 17:01 - 2015-09-29 05:05 - 03936192 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-10-14 17:01 - 2015-09-29 05:02 - 01308160 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-10-14 17:01 - 2015-09-29 04:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-10-14 17:01 - 2015-09-29 04:58 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2015-10-14 17:01 - 2015-09-29 04:58 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-10-14 17:01 - 2015-09-29 04:53 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-10-14 17:01 - 2015-09-29 04:53 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-10-14 17:01 - 2015-09-29 04:49 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-10-14 17:01 - 2015-09-29 04:49 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-10-14 17:01 - 2015-09-29 03:43 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-10-14 17:01 - 2015-09-29 03:43 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-10-14 17:01 - 2015-09-29 03:43 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-10-14 17:01 - 2015-09-15 19:42 - 00139096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-10-14 17:01 - 2015-09-15 19:42 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-10-14 17:01 - 2015-09-15 19:36 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-10-14 17:01 - 2015-09-15 19:36 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-10-14 17:01 - 2015-09-15 19:35 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-10-14 17:01 - 2015-07-18 15:08 - 00901264 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00066400 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00022368 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2015-10-14 17:01 - 2015-07-18 15:08 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2015-10-14 17:00 - 2015-10-14 17:00 - 00275856 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2015-10-14 16:31 - 2015-08-06 19:44 - 12875776 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-10-14 16:31 - 2015-08-06 19:44 - 01498624 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-10-12 00:06 - 2015-10-12 00:06 - 00000000 ____D C:\Users\benjamin sufner\AppData\Local\MyBrowser
2015-10-06 17:28 - 2015-10-06 17:28 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsnE25.tmp
2015-10-06 17:27 - 2015-10-14 18:35 - 00001184 _____ C:\task.vbs
2015-10-05 19:27 - 2015-10-05 19:27 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiC321.tmp
2015-10-04 10:28 - 2015-10-04 10:28 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nssF748.tmp
2015-10-03 19:22 - 2015-10-03 19:22 - 00001724 _____ C:\Users\Helca\Desktop\Play SimCity 2013 Offline.lnk
2015-10-03 19:16 - 2015-10-03 19:22 - 00000000 ____D C:\Games
2015-10-03 17:44 - 2015-10-03 19:24 - 00000000 ____D C:\Users\Helca\AppData\Roaming\uTorrent
2015-10-03 17:32 - 2015-10-03 17:32 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsd450.tmp
2015-10-03 12:32 - 2015-10-03 12:32 - 00000000 ____D C:\Users\Helca\Documents\SimCity
2015-10-03 12:07 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-10-03 12:07 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-10-03 12:07 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-10-03 12:07 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-10-03 12:07 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-10-03 12:07 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-10-03 12:07 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-10-03 12:07 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-10-03 12:07 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-10-03 12:07 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-10-03 12:07 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-10-03 12:07 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-10-03 12:07 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-10-03 12:07 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-10-03 12:07 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-10-03 12:07 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-10-03 12:07 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-10-03 12:07 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-10-03 12:07 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-10-03 12:07 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-10-03 12:07 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-10-03 12:07 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-10-03 11:40 - 2015-10-03 11:40 - 00000000 ____D C:\Windows\system32\Flash
2015-10-03 11:37 - 2015-10-03 11:37 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsu35BB.tmp
2015-10-02 14:04 - 2015-10-02 14:04 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsn4DFF.tmp
2015-09-29 18:46 - 2015-09-29 18:01 - 00613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiBFE3.tmp
2015-09-29 18:22 - 2015-09-29 18:22 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-09-29 18:06 - 2015-09-29 18:06 - 00001092 _____ C:\Users\Helca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-29 18:06 - 2015-09-29 18:06 - 00001092 _____ C:\Users\benjamin sufner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-09-28 12:47 - 2015-10-14 19:28 - 00000000 ____D C:\Users\Helca\AppData\Roaming\Seznam.cz
2015-09-28 12:47 - 2015-10-14 19:26 - 00000000 ____D C:\Program Files\Seznam.cz
2015-09-28 12:43 - 2015-10-16 00:54 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-09-28 12:36 - 2015-09-28 12:37 - 00000000 ____D C:\Users\Helca\AppData\Roaming\Opera Software
2015-09-28 12:36 - 2015-09-28 12:37 - 00000000 ____D C:\Users\Helca\AppData\Local\Opera Software
2015-09-28 12:34 - 2015-09-28 12:37 - 00000000 ____D C:\Program Files\Opera
2015-09-28 12:33 - 2015-09-28 12:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-09-28 12:32 - 2015-09-28 12:32 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-28 12:32 - 2009-06-10 23:39 - 00000824 _____ C:\Windows\system32\Drivers\etc\hp.bak
2015-09-27 14:25 - 2015-09-27 14:25 - 00000000 ____D C:\.oracle_jre_usage
2015-09-25 13:52 - 2015-09-25 13:52 - 00001296 _____ C:\Users\Public\Desktop\The Sims 4.lnk
2015-09-25 13:52 - 2015-09-25 13:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Sims 4
2015-09-23 06:50 - 2015-10-03 18:43 - 00000000 ____D C:\Users\Helca\Desktop\Mods
2015-09-22 11:35 - 2015-05-06 17:07 - 00295906 _____ C:\Users\Helca\Desktop\BeachBackground_Annett85 (5).package
2015-09-22 11:28 - 2015-09-22 11:29 - 00000000 ____D C:\Users\benjamin sufner\Desktop\Mods
2015-09-21 15:25 - 2015-09-21 15:00 - 00381913 _____ C:\Users\Helca\Desktop\BeachBackground_Annett85 (2).package
2015-09-21 15:17 - 2015-09-21 15:18 - 351470129 _____ C:\Users\Helca\Desktop\stažené soubory.zip
2015-09-21 15:17 - 2015-09-21 15:17 - 00000000 ____D C:\Users\Helca\Desktop\stažené soubory
2015-09-21 14:59 - 2015-06-14 17:05 - 00298848 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau3.package
2015-09-21 14:59 - 2015-06-14 16:48 - 00284483 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau2.package
2015-09-21 14:59 - 2015-06-14 16:36 - 00300097 _____ C:\Users\benjamin sufner\Desktop\HintergrundBlau1.package
2015-09-21 14:59 - 2015-05-13 15:20 - 00000584 _____ C:\Users\benjamin sufner\Desktop\Credits.txt
2015-09-21 14:58 - 2015-05-06 17:07 - 00295906 _____ C:\Users\benjamin sufner\Desktop\BeachBackground_Annett85 (5).package
2015-09-21 14:56 - 2015-09-21 14:56 - 00000000 ____D C:\Users\benjamin sufner\AppData\Local\CrashDumps

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-17 17:22 - 2015-09-01 00:11 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d0e43a941c0ec.job
2015-10-17 17:15 - 2015-06-03 18:52 - 00000177 ____H C:\dvmexp.idx
2015-10-17 17:15 - 2015-06-03 17:43 - 01564873 _____ C:\Windows\WindowsUpdate.log
2015-10-17 14:13 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-10-17 12:43 - 2015-08-16 20:35 - 00000000 ____D C:\ProgramData\Origin
2015-10-17 12:43 - 2009-07-14 06:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-17 12:43 - 2009-07-14 06:34 - 00014608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-17 12:38 - 2015-06-03 18:23 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-17 12:35 - 2015-09-01 00:11 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e43a86c6dc6.job
2015-10-17 12:35 - 2015-06-04 18:53 - 00000043 _____ C:\Users\Public\Documents\AtherosServiceConfig.ini
2015-10-17 12:35 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-17 12:34 - 2015-06-09 18:49 - 00000000 ____D C:\ProgramData\NVIDIA
2015-10-17 12:32 - 2014-05-18 19:37 - 00000000 ____D C:\AdwCleaner
2015-10-17 09:27 - 2015-06-09 03:22 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-10-17 09:27 - 2015-06-09 03:22 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-17 09:25 - 2015-06-04 18:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-16 00:30 - 2015-07-29 16:58 - 00001972 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2015-10-16 00:30 - 2015-07-29 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-10-16 00:29 - 2015-06-03 18:29 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-10-15 07:59 - 2015-06-14 13:53 - 00000000 ____D C:\Windows\system32\MRT
2015-10-15 07:42 - 2015-06-14 13:52 - 141105520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-10-14 17:58 - 2015-06-03 18:26 - 00000000 ____D C:\Users\Helca
2015-10-14 17:31 - 2015-08-17 09:13 - 00000000 ____D C:\Users\Helca\AppData\Local\CrashDumps
2015-10-09 14:37 - 2015-08-17 04:15 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-03 17:48 - 2015-08-16 20:39 - 00000000 ____D C:\Program Files\Origin Games
2015-10-03 17:48 - 2009-07-14 06:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-09-29 18:22 - 2015-06-04 18:32 - 00434184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00208664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00115640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00081728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00076000 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-09-29 18:22 - 2015-06-04 18:32 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-09-29 18:21 - 2015-09-05 17:25 - 00107984 _____ (AVAST Software) C:\Windows\system32\Drivers\ngvss.sys
2015-09-29 18:21 - 2015-06-04 18:32 - 00789296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-09-25 17:19 - 2015-08-16 20:34 - 00000000 ____D C:\Program Files\Origin
2015-09-25 16:56 - 2015-08-16 20:34 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-09-22 12:32 - 2015-06-09 19:33 - 00000000 ____D C:\Program Files\Minecraft
2015-09-21 15:49 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles
2015-09-20 20:02 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-18 07:07 - 2015-06-04 17:54 - 00000000 ____D C:\Users\Helca\AppData\Local\Google

==================== Files in the root of some directories =======

2015-10-03 17:32 - 2015-10-03 17:32 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsd450.tmp
2015-09-29 18:46 - 2015-09-29 18:01 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiBFE3.tmp
2015-10-05 19:27 - 2015-10-05 19:27 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsiC321.tmp
2015-10-02 14:04 - 2015-10-02 14:04 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsn4DFF.tmp
2015-10-06 17:28 - 2015-10-06 17:28 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsnE25.tmp
2015-10-04 10:28 - 2015-10-04 10:28 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nssF748.tmp
2015-10-03 11:37 - 2015-10-03 11:37 - 0613255 _____ (CMI Limited) C:\Users\Helca\AppData\Local\nsu35BB.tmp
2015-09-28 12:43 - 2015-10-16 00:54 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Some files in TEMP:
====================
C:\Users\Helca\AppData\Local\Temp\3187.exe
C:\Users\Helca\AppData\Local\Temp\3353.exe
C:\Users\Helca\AppData\Local\Temp\5847.exe
C:\Users\Helca\AppData\Local\Temp\7672.exe
C:\Users\Helca\AppData\Local\Temp\8103.exe
C:\Users\Helca\AppData\Local\Temp\885.exe
C:\Users\Helca\AppData\Local\Temp\9265.exe
C:\Users\Helca\AppData\Local\Temp\fsd39B5.exe
C:\Users\Helca\AppData\Local\Temp\fsd8C97.exe
C:\Users\Helca\AppData\Local\Temp\sqlite3.dll
C:\Users\Helca\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-11 23:25

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: adware-gen, evo-gen, v chrome mystartsearch

#7 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Run: [GoogleChromeAutoLaunch_86C0A2F254862841B3FCDAAA457F4271] => C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe [636928 2015-08-29] (MyBrowser)
C:\Program Files\MyBrowser
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://www.google.cz/ ... kid=sp-006"
CHR DefaultSearchURL: Default -> hxxp://www.mystartsearch.com/web/?type= ... B209622&q={searchTerms}
CHR DefaultSearchKeyword: Default -> mystartsearch
C:\Users\Public\Desktop\MyBrowser.lnk
C:\Windows\Tasks\MyBrowser.job
c:\Users\Helca\AppData\Local\nsd450.tmp
C:\Users\Helca\AppData\Local\nsu35BB.tmp
C:\Users\Helca\AppData\Local\nsn4DFF.tmp
C:\Users\Helca\AppData\Local\nsiBFE3.tmp
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e43a86c6dc6.job
C:\Users\Helca\AppData\Local\nsd450.tmp
C:\Users\Helca\AppData\Local\nsiBFE3.tmp
C:\Users\Helca\AppData\Local\nsiC321.tmp
C:\Users\Helca\AppData\Local\nsn4DFF.tmp
C:\Users\Helca\AppData\Local\nsnE25.tmp
C:\Users\Helca\AppData\Local\nssF748.tmp
C:\Users\Helca\AppData\Local\nsu35BB.tmp
C:\Users\Helca\AppData\Local\Temp
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

Re: adware-gen, evo-gen, v chrome mystartsearch

#8 Příspěvek od mandra »

Dobré ráno, tady je log....

Fix result of Farbar Recovery Scan Tool (x86) Version:17-10-2015
Ran by Helca (2015-10-18 09:13:55) Run:1
Running from C:\Users\Helca\Desktop
Loaded Profiles: Helca (Available Profiles: Helca & benjamin sufner)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\...\Run: [GoogleChromeAutoLaunch_86C0A2F254862841B3FCDAAA457F4271] => C:\Program Files\MyBrowser\MyBrowser\Application\mybrowser.exe [636928 2015-08-29] (MyBrowser)
C:\Program Files\MyBrowser
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxps://www.google.cz/ ... kid=sp-006"
CHR DefaultSearchURL: Default -> hxxp://www.mystartsearch.com/web/?type= ... B209622&q={searchTerms}
CHR DefaultSearchKeyword: Default -> mystartsearch
C:\Users\Public\Desktop\MyBrowser.lnk
C:\Windows\Tasks\MyBrowser.job
c:\Users\Helca\AppData\Local\nsd450.tmp
C:\Users\Helca\AppData\Local\nsu35BB.tmp
C:\Users\Helca\AppData\Local\nsn4DFF.tmp
C:\Users\Helca\AppData\Local\nsiBFE3.tmp
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e43a86c6dc6.job
C:\Users\Helca\AppData\Local\nsd450.tmp
C:\Users\Helca\AppData\Local\nsiBFE3.tmp
C:\Users\Helca\AppData\Local\nsiC321.tmp
C:\Users\Helca\AppData\Local\nsn4DFF.tmp
C:\Users\Helca\AppData\Local\nsnE25.tmp
C:\Users\Helca\AppData\Local\nssF748.tmp
C:\Users\Helca\AppData\Local\nsu35BB.tmp
C:\Users\Helca\AppData\Local\Temp
End
*****************

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully.
HKU\S-1-5-21-3585771554-1706488130-264146928-1000\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_86C0A2F254862841B3FCDAAA457F4271 => value removed successfully.

"C:\Program Files\MyBrowser" folder move:

Could not move "C:\Program Files\MyBrowser" => Scheduled to move on reboot.

Chrome StartupUrls => removed successfully.
Chrome DefaultSearchURL => removed successfully.
Chrome DefaultSearchKeyword => removed successfully.
C:\Users\Public\Desktop\MyBrowser.lnk => moved successfully
C:\Windows\Tasks\MyBrowser.job => moved successfully
c:\Users\Helca\AppData\Local\nsd450.tmp => moved successfully
C:\Users\Helca\AppData\Local\nsu35BB.tmp => moved successfully
C:\Users\Helca\AppData\Local\nsn4DFF.tmp => moved successfully
C:\Users\Helca\AppData\Local\nsiBFE3.tmp => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e43a86c6dc6.job => moved successfully
"C:\Users\Helca\AppData\Local\nsd450.tmp" => File/Folder not found.
"C:\Users\Helca\AppData\Local\nsiBFE3.tmp" => File/Folder not found.
C:\Users\Helca\AppData\Local\nsiC321.tmp => moved successfully
"C:\Users\Helca\AppData\Local\nsn4DFF.tmp" => File/Folder not found.
C:\Users\Helca\AppData\Local\nsnE25.tmp => moved successfully
C:\Users\Helca\AppData\Local\nssF748.tmp => moved successfully
"C:\Users\Helca\AppData\Local\nsu35BB.tmp" => File/Folder not found.

"C:\Users\Helca\AppData\Local\Temp" folder move:

Could not move "C:\Users\Helca\AppData\Local\Temp" => Scheduled to move on reboot.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-10-18 09:16:47)

C:\Program Files\MyBrowser => is moved successfully
"C:\Users\Helca\AppData\Local\Temp" => Could not move

==== End of Fixlog 09:16:49 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: adware-gen, evo-gen, v chrome mystartsearch

#9 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

mandra
Návštěvník
Návštěvník
Příspěvky: 34
Registrován: 26 čer 2007 00:24

Re: adware-gen, evo-gen, v chrome mystartsearch

#10 Příspěvek od mandra »

zatím to vypadá, že jsme se neřáda zbavili :|

Děkuji mnohokrát :thumbsup:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: adware-gen, evo-gen, v chrome mystartsearch

#11 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno