Zpomalení pc, pop up ads
Napsal: 18 led 2016 17:05
Zdravím a prosím o pomoc při čištění kamarádova pc. Zabalastoval to nejspíš v rámci shánění licenčních klíčů.
Pc je zasekanej a v pravým horním rohu reklama za reklamou.
Při startu se nově "Řízení uživatelských účtů" táže, jestli povolit program "MTview" od "Zhu Weiqin"
Log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-01-2015
Ran by Hanzka (administrator) on HANZKA-PC (18-01-2016 16:36:57)
Running from C:\Users\Hanzka\Desktop
Loaded Profiles: Hanzka (Available Profiles: Hanzka & Mcx1-HANZKA-PC)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\t_201601170512\201601170512\lsas.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
( ) C:\Program Files (x86)\t_201601170512\201601170512\auds.exe
() C:\Program Files (x86)\t_201601170512\201601170512\tslog.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
( ) C:\Program Files (x86)\t_201601170512\201601170512\auds.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(forum.viry.cz) C:\Users\Hanzka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM-x32\...\Run: [MSStp] => C:\Windows\system32\msstp.vbe
HKLM-x32\...\Run: [MTview] => C:\Program Files (x86)\MTV20151125\MTView.exe [1875464 2015-11-25] (STA)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2016-01-17] (AVAST Software)
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\Run: [lsas] => C:\Program Files (x86)\t_201601170512\201601170512\lsas.exe [557184 2016-01-17] ()
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\MountPoints2: {f1488940-1503-11e5-8bef-00265e9bfa37} - F:\Lenovo_Suite.exe
AppInit_DLLs: C:\ProgramData\caMyciloP\Konkdom.dll => C:\ProgramData\caMyciloP\Konkdom.dll [805376 2016-01-17] ()
AppInit_DLLs-x32: C:\ProgramData\caMyciloP\Biglux.dll => C:\ProgramData\caMyciloP\Biglux.dll [257536 2016-01-17] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-01-17] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-17]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-2950201998-2485440076-3267433508-1000] => hxxp://unstopp.me/wpad.dat?39a768e41d4e4b1336682c786c7aa6b04433658
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FA635ED2-CD5F-46BF-B766-4CC57E9E686C}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {215A8782-A592-46D6-9BB1-7C22FFDCD30B} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=623
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {65AC85CC-BF20-4E97-986C-BA05CE85EADD} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {A060E7FB-91F5-4c7c-BD0F-4A11A581D878} URL = hxxps://www.baidu.com/s?wd={searchTerms}&tn=98012088_5_dg&ch=11
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-01-17] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-17] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default
FF DefaultSearchEngine: Yahoo! Search
FF Homepage: C:\ProgramData\caMyciloPs\ff.HP
FF SearchEngineOrder.1: WebSearch
FF SelectedSearchEngine: Yahoo! Search
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Keyword.URL:
FF DefaultSearchUrl: hxxp://websearch.allsearches.info/?pid=3521&r=2014/10/09&hid=4176657213035267658&lg=EN&cc=CZ&unqvl=64&l=1&q=
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF NewTab: C:\ProgramData\caMyciloPs\ff.NT
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-26] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-26] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=0.9.9 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2009-03-31] (the VideoLAN Team)
FF user.js: detected! => C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\user.js [2014-10-05]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\findit.xml [2016-01-17]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\firmycz.xml [2014-10-05]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\zbocz.xml [2014-10-05]
FF Extension: No Name - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Extension: No Name - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\extensions\sonnypenn@aol.com [not found]
FF Extension: WinToFlash Suggestor - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\Extensions\{285ACFBB-8E53-4feb-90E6-F02A128927F3}.xpi [2012-05-25] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-17]
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://feed.wiki-search.me/?st=ds&query={searchTerms}
CHR DefaultSearchKeyword: Default -> Wiki Search.me
CHR Profile: C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-04]
CHR Extension: (WinToFlash Suggestor) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\acaoakiamfeidcmgooclgeleejkbaecf [2015-04-05] [UpdateUrl: hxxp://wintoflashsuggestor.net/update/updatecheckchrome-10045.xml] <==== ATTENTION
CHR Extension: (Dokumenty Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-04]
CHR Extension: (Disk Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2016-01-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-01-17]
CHR Extension: (YouTube) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28]
CHR Extension: (Vyhledávání Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Tabulky Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-04]
CHR Extension: (AdBlock) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-17]
CHR Extension: (Avast Online Security) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-01-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-15]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2016-01-17]
CHR Extension: (Mahjong Zahrady) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfekddiiamgblmgoodjgkfmkehnepljb [2015-12-21]
CHR Extension: (Gmail) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR HKLM-x32\...\Chrome\Extension: [acaoakiamfeidcmgooclgeleejkbaecf] - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.crx [2012-05-25]
CHR HKLM-x32\...\Chrome\Extension: [fcgnigmofekcllgbiejhmigggmgehkip] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-01-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2016-01-17] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109520 2016-01-17] (AVAST Software)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [619776 2014-12-24] (Lenovo)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [289256 2015-12-02] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-20] (Electronic Arts)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 QQPCRTP; "C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\QQPCRtp.exe" -r [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2016-01-17] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2016-01-17] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2016-01-17] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [466400 2016-01-17] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2016-01-17] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2016-01-17] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2016-01-17] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2016-01-17] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2016-01-17] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2016-01-17] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-05] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [45368 2015-12-28] (电脑管家)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S1 QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\QMUdisk64.sys [X]
S1 softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\softaal64.sys [X]
S1 TsDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\TsDefenseBT64.sys [X]
S2 tsnethlpx64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\TsNetHlpX64.sys [X]
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-18 16:36 - 2016-01-18 16:37 - 00019025 _____ C:\Users\Hanzka\Desktop\FRST.txt
2016-01-18 16:36 - 2016-01-18 16:36 - 00000000 ____D C:\FRST
2016-01-18 16:34 - 2016-01-18 16:34 - 02370560 _____ (Farbar) C:\Users\Hanzka\Desktop\FRST64.exe
2016-01-18 16:34 - 2016-01-18 16:34 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Desktop\FRSTLauncher.exe
2016-01-18 16:32 - 2016-01-18 16:32 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Downloads\Nepotvrzeno 8292.crdownload
2016-01-18 16:32 - 2016-01-18 16:32 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Downloads\Nepotvrzeno 431638.crdownload
2016-01-18 15:42 - 2012-11-29 23:27 - 00000000 ____D C:\Users\Hanzka\Downloads\Ableton Live 8.2.2 (CRACKED) [theLEAK]
2016-01-18 01:49 - 2016-01-18 03:34 - 1765020148 _____ C:\Users\Hanzka\Downloads\Ableton-Live-8.2.2-(CRACKED)-[theLEAK].rar
2016-01-17 23:52 - 2016-01-17 23:52 - 00003034 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1453071148
2016-01-17 23:52 - 2016-01-17 23:52 - 00001037 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-01-17 23:52 - 2016-01-17 23:52 - 00001037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-01-17 23:51 - 2016-01-17 23:50 - 00028144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-01-17 23:51 - 2016-01-17 23:45 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-01-17 23:48 - 2016-01-17 23:48 - 00001922 _____ C:\Users\Public\Desktop\Avast Premier.lnk
2016-01-17 23:48 - 2016-01-17 23:48 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\AVAST Software
2016-01-17 23:48 - 2016-01-17 23:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-01-17 23:46 - 2016-01-17 23:51 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-01-17 23:46 - 2016-01-17 23:46 - 00451040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-01-17 23:46 - 2016-01-17 23:46 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-01-17 23:46 - 2016-01-17 23:46 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-01-17 23:46 - 2016-01-17 23:46 - 00000000 ____D C:\Program Files\Common Files\AV
2016-01-17 23:46 - 2016-01-17 23:45 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-01-17 23:45 - 2016-01-17 23:45 - 00466400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2016-01-17 23:45 - 2016-01-17 23:45 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-01-17 23:44 - 2016-01-17 23:50 - 00000000 ____D C:\Program Files\AVAST Software
2016-01-17 23:44 - 2016-01-17 23:44 - 05037024 _____ (AVAST Software) C:\Users\Hanzka\Downloads\avast_premier_antivirus_setup_online.exe
2016-01-17 23:40 - 2016-01-18 00:17 - 00000000 ____D C:\ProgramData\caMyciloP
2016-01-17 23:40 - 2016-01-17 23:41 - 00000000 ____D C:\ProgramData\caMyciloPs
2016-01-17 23:38 - 2016-01-17 23:38 - 00290880 _____ C:\Windows\Minidump\011716-50528-01.dmp
2016-01-17 23:37 - 2016-01-17 23:37 - 629821633 _____ C:\Windows\MEMORY.DMP
2016-01-17 21:42 - 2016-01-17 21:42 - 00003096 _____ C:\Windows\System32\Tasks\{834FB3E9-7287-47C0-ABBD-005ED353C89F}
2016-01-17 21:33 - 2016-01-17 21:33 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Apowersoft
2016-01-17 21:33 - 2016-01-17 21:33 - 00000000 ____D C:\ProgramData\Apowersoft
2016-01-17 21:32 - 2016-01-17 21:34 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Apowersoft
2016-01-17 21:22 - 2016-01-17 21:22 - 00003562 _____ C:\Windows\System32\Tasks\{0D48CCDF-75F9-438D-A022-83E470529879}
2016-01-17 17:33 - 2016-01-17 17:33 - 00005120 _____ C:\Users\Hanzka\AppData\Roaming\GiftBag.db
2016-01-17 17:29 - 2016-01-17 17:29 - 00000000 ____D C:\Program Files (x86)\t_201601171729
2016-01-17 07:18 - 2016-01-17 07:18 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\vstsaxi
2016-01-17 06:17 - 2016-01-17 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-01-17 06:02 - 2016-01-17 06:14 - 00000000 ____D C:\Users\Hanzka\Documents\Ableton
2016-01-17 06:00 - 2016-01-18 16:08 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Ableton
2016-01-17 05:57 - 2016-01-17 23:07 - 00000000 ____D C:\ProgramData\Ableton
2016-01-17 05:57 - 2016-01-17 05:57 - 00000881 _____ C:\Users\Hanzka\Desktop\Ableton Live 9 Trial.lnk
2016-01-17 05:39 - 2016-01-17 23:40 - 00002397 _____ C:\Windows\SysWOW64\findit.xml
2016-01-17 05:39 - 2016-01-17 08:39 - 00000000 ____D C:\Program Files\cmdidx
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\ProgramData\Medlights
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-01-17 05:38 - 2016-01-18 00:17 - 00000000 ____D C:\ProgramData\Medlight
2016-01-17 05:27 - 2016-01-17 05:27 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\SimpleFiles
2016-01-17 05:16 - 2016-01-17 05:16 - 00000000 ____D C:\ProgramData\TXQMPC
2016-01-17 05:15 - 2016-01-17 17:45 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-01-17 05:15 - 2016-01-17 17:29 - 00087864 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFltX64.sys
2016-01-17 05:15 - 2016-01-17 05:15 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-01-17 05:15 - 2015-12-28 16:34 - 00045368 _____ (电脑管家) C:\Windows\system32\Drivers\TSSKX64.sys
2016-01-17 05:14 - 2016-01-17 05:38 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Tencent
2016-01-17 05:14 - 2016-01-17 05:30 - 00000000 ____D C:\ProgramData\Tencent
2016-01-17 05:14 - 2016-01-17 05:14 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-01-17 05:12 - 2016-01-17 05:12 - 00000000 ____D C:\Program Files (x86)\t_201601170512
2016-01-17 05:11 - 2016-01-17 07:30 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2016-01-17 05:11 - 2016-01-17 05:12 - 00000000 ____D C:\Program Files (x86)\MTV20151125
2016-01-17 05:11 - 2016-01-17 05:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ĂŔÍĽäŻŔŔ
2016-01-17 04:44 - 2016-01-17 05:18 - 00002568 _____ C:\Users\Hanzka\Documents\Register ACID Pro.htm
2016-01-17 04:42 - 2016-01-17 04:42 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Sony
2016-01-17 04:37 - 2016-01-17 04:37 - 00000000 ____D C:\Program Files (x86)\Sony Setup
2016-01-17 04:32 - 2016-01-17 04:38 - 701280372 _____ C:\Users\Hanzka\Downloads\ableton_live_trial_9-1-1_32.zip
2016-01-17 04:07 - 2016-01-17 04:07 - 00000394 _____ C:\Users\Hanzka\Documents\mm.ilcontrol
2015-12-21 21:18 - 2015-12-21 21:18 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-21 14:43 - 2012-02-15 14:02 - 00000000 ____D C:\Users\Hanzka\Downloads\AudioRealism_Bass_Line_VSTi_v2.5.0
2015-12-21 14:42 - 2015-12-21 14:42 - 00000000 ____D C:\Users\Hanzka\Downloads\Nová složka
2015-12-20 16:29 - 2015-12-20 16:37 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Origin
2015-12-20 16:29 - 2015-12-20 16:29 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Origin
2015-12-20 16:27 - 2015-12-20 16:39 - 00000000 ____D C:\ProgramData\Origin
2015-12-20 16:27 - 2015-12-20 16:27 - 00000983 _____ C:\Users\Hanzka\Documents\Origin.lnk
2015-12-20 16:27 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-12-20 16:27 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-12-20 16:26 - 2015-12-20 16:29 - 00000000 ____D C:\Program Files (x86)\Origin
2015-12-20 16:26 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-20 01:00 - 2015-12-21 14:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioRealism Bass Line 2
2015-12-20 01:00 - 2015-12-20 01:00 - 00000000 ____D C:\Users\Hanzka\Documents\AudioRealism
2015-12-20 00:56 - 2015-12-20 00:56 - 00000000 ____D C:\Users\Hanzka\Downloads\Install_ABL2_WIN64
2015-12-19 20:57 - 2015-12-20 16:31 - 00000192 _____ C:\Users\Hanzka\Documents\hesla.txt
2015-12-19 03:00 - 2015-12-19 03:00 - 00000000 ____D C:\Users\Hanzka\Documents\Tom_hp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-18 16:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-01-18 16:23 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-18 16:23 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-18 16:21 - 2015-10-12 19:26 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-18 16:20 - 2009-07-14 16:18 - 00668376 _____ C:\Windows\system32\perfh005.dat
2016-01-18 16:20 - 2009-07-14 16:18 - 00141004 _____ C:\Windows\system32\perfc005.dat
2016-01-18 16:20 - 2009-07-14 06:13 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-18 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-01-18 16:16 - 2014-12-26 12:45 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-18 16:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-18 15:50 - 2014-12-26 12:45 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-18 00:19 - 2014-10-08 22:18 - 00000000 ____D C:\ProgramData\NNExtCoeUp
2016-01-17 23:51 - 2014-10-05 03:20 - 00000000 ____D C:\ProgramData\AVAST Software
2016-01-17 23:41 - 2014-12-26 12:46 - 00002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-17 23:41 - 2014-10-02 13:03 - 00001459 _____ C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-17 23:38 - 2014-10-08 22:08 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-01-17 23:38 - 2014-10-06 00:13 - 00000000 ____D C:\Windows\Minidump
2016-01-17 23:37 - 2009-07-14 05:45 - 00278568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-17 21:47 - 2014-10-05 23:35 - 00000000 ____D C:\Program Files (x86)\Image-Line
2016-01-17 21:41 - 2014-10-13 14:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-01-17 21:41 - 2014-10-02 22:44 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-01-17 21:40 - 2015-10-12 21:10 - 00000000 ____D C:\Program Files (x86)\Winamp
2016-01-17 21:40 - 2014-10-13 14:16 - 00000000 ____D C:\Program Files (x86)\VstPlugins
2016-01-17 07:31 - 2014-10-05 03:39 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Seznam.cz
2016-01-17 07:16 - 2014-10-02 15:27 - 00059104 _____ C:\Users\Hanzka\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-17 05:18 - 2015-10-21 18:21 - 00020522 _____ C:\ProgramData\svchost.exe.tmp
2016-01-17 01:59 - 2015-07-15 00:14 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-14 07:13 - 2014-10-06 16:50 - 00003848 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1412610607
2016-01-14 07:13 - 2014-10-06 16:50 - 00000000 ____D C:\Program Files (x86)\Opera
2016-01-05 05:56 - 2014-10-26 22:47 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\dvdcss
2016-01-04 18:09 - 2015-03-06 20:34 - 00000000 ____D C:\Users\Hanzka\Documents\hlasky
2016-01-03 19:23 - 2015-10-12 19:26 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-01-03 19:23 - 2014-10-05 21:08 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-03 19:23 - 2014-10-05 21:08 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-31 11:17 - 2014-10-02 13:00 - 00000000 ____D C:\Users\Hanzka
2015-12-29 11:22 - 2015-07-15 00:14 - 00003956 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
==================== Files in the root of some directories =======
2016-01-17 17:33 - 2016-01-17 17:33 - 0005120 _____ () C:\Users\Hanzka\AppData\Roaming\GiftBag.db
2014-10-08 22:10 - 2014-10-08 22:10 - 0000323 _____ () C:\Users\Hanzka\AppData\Roaming\LiveSupport.exe_log.txt
2014-10-08 22:10 - 2014-10-08 22:15 - 0000092 _____ () C:\Users\Hanzka\AppData\Roaming\regsvr32.exe_log.txt
2014-10-05 03:48 - 2014-10-05 03:48 - 0225280 _____ (Propellerhead Software AB) C:\Users\Hanzka\AppData\Roaming\Rewire.dll
2014-10-05 03:48 - 2014-10-05 03:48 - 0233472 _____ (Propellerhead Software AB) C:\Users\Hanzka\AppData\Roaming\REX Shared Library.dll
2015-10-21 18:21 - 2016-01-17 05:18 - 0020522 _____ () C:\ProgramData\svchost.exe.tmp
Files to move or delete:
====================
C:\Users\Hanzka\FL Studio VSTi (Multi).dll
C:\Users\Hanzka\FL Studio VSTi.dll
Some files in TEMP:
====================
C:\Users\Hanzka\AppData\Local\Temp\01d363ca.exe
C:\Users\Hanzka\AppData\Local\Temp\7z938.exe
C:\Users\Hanzka\AppData\Local\Temp\Ableton Swapper.exe
C:\Users\Hanzka\AppData\Local\Temp\amt_omniboxes.exe
C:\Users\Hanzka\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Hanzka\AppData\Local\Temp\deckadance_install.exe
C:\Users\Hanzka\AppData\Local\Temp\DriverSupport.exe
C:\Users\Hanzka\AppData\Local\Temp\drvprosetup.exe
C:\Users\Hanzka\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Hanzka\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Hanzka\AppData\Local\Temp\findamo.exe
C:\Users\Hanzka\AppData\Local\Temp\GC_PCTOOLS.exe
C:\Users\Hanzka\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Hanzka\AppData\Local\Temp\mslog.dll
C:\Users\Hanzka\AppData\Local\Temp\msxml6-KB927977-enu-x86.exe
C:\Users\Hanzka\AppData\Local\Temp\nircmd.exe
C:\Users\Hanzka\AppData\Local\Temp\nsm1BA7.exe
C:\Users\Hanzka\AppData\Local\Temp\ochelper.exe
C:\Users\Hanzka\AppData\Local\Temp\optprosetup.exe
C:\Users\Hanzka\AppData\Local\Temp\PCMgr_Setup_11_3_17202_219.exe
C:\Users\Hanzka\AppData\Local\Temp\pcspeedup.exe
C:\Users\Hanzka\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881436_Silence.exe
C:\Users\Hanzka\AppData\Local\Temp\rar.exe
C:\Users\Hanzka\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Hanzka\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Hanzka\AppData\Local\Temp\somoto_chrome.exe
C:\Users\Hanzka\AppData\Local\Temp\Tinyxml2.dll
C:\Users\Hanzka\AppData\Local\Temp\tmp4F17.tmp.exe
C:\Users\Hanzka\AppData\Local\Temp\utt69F7.tmp.exe
C:\Users\Hanzka\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Users\Hanzka\AppData\Local\Temp\~6080.exe
C:\Users\Hanzka\AppData\Local\Temp\~662B.exe
C:\Users\Hanzka\AppData\Local\Temp\~B3CF.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_20_0_0_267_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Hanzka\Desktop" je 2 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Pc je zasekanej a v pravým horním rohu reklama za reklamou.
Při startu se nově "Řízení uživatelských účtů" táže, jestli povolit program "MTview" od "Zhu Weiqin"
Log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-01-2015
Ran by Hanzka (administrator) on HANZKA-PC (18-01-2016 16:36:57)
Running from C:\Users\Hanzka\Desktop
Loaded Profiles: Hanzka (Available Profiles: Hanzka & Mcx1-HANZKA-PC)
Platform: Windows 7 Home Premium (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files (x86)\t_201601170512\201601170512\lsas.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe
( ) C:\Program Files (x86)\t_201601170512\201601170512\auds.exe
() C:\Program Files (x86)\t_201601170512\201601170512\tslog.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
( ) C:\Program Files (x86)\t_201601170512\201601170512\auds.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\34.0.2036.47\opera.exe
(forum.viry.cz) C:\Users\Hanzka\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM-x32\...\Run: [MSStp] => C:\Windows\system32\msstp.vbe
HKLM-x32\...\Run: [MTview] => C:\Program Files (x86)\MTV20151125\MTView.exe [1875464 2015-11-25] (STA)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2016-01-17] (AVAST Software)
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\Run: [lsas] => C:\Program Files (x86)\t_201601170512\201601170512\lsas.exe [557184 2016-01-17] ()
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\...\MountPoints2: {f1488940-1503-11e5-8bef-00265e9bfa37} - F:\Lenovo_Suite.exe
AppInit_DLLs: C:\ProgramData\caMyciloP\Konkdom.dll => C:\ProgramData\caMyciloP\Konkdom.dll [805376 2016-01-17] ()
AppInit_DLLs-x32: C:\ProgramData\caMyciloP\Biglux.dll => C:\ProgramData\caMyciloP\Biglux.dll [257536 2016-01-17] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-01-17] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-17]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-2950201998-2485440076-3267433508-1000] => hxxp://unstopp.me/wpad.dat?39a768e41d4e4b1336682c786c7aa6b04433658
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{FA635ED2-CD5F-46BF-B766-4CC57E9E686C}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2950201998-2485440076-3267433508-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
SearchScopes: HKLM-x32 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {215A8782-A592-46D6-9BB1-7C22FFDCD30B} URL = hxxp://q.search-simple.com/?affID=na&q={searchTerms}&r=623
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {65AC85CC-BF20-4E97-986C-BA05CE85EADD} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {A060E7FB-91F5-4c7c-BD0F-4A11A581D878} URL = hxxps://www.baidu.com/s?wd={searchTerms}&tn=98012088_5_dg&ch=11
SearchScopes: HKU\S-1-5-21-2950201998-2485440076-3267433508-1000 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRYEqQao2TxTGptbOxpBNaVXAdGTZAYinpmLi9tRWXORUvcZtxJmuvoSgZs4cV5r1KoH_Dkpozz8lDe9VF5QAd4CbRnIfPiInJMYHShsCbLqIbApVmdKcx3yfHSk0tdpoWT1mqXK3klE4ZpXnsGnL5FdhPW3-p8lNL4AfhG_NOiEOUITFD-xngafANqvqumI,&q={searchTerms}
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-01-17] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-01-17] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default
FF DefaultSearchEngine: Yahoo! Search
FF Homepage: C:\ProgramData\caMyciloPs\ff.HP
FF SearchEngineOrder.1: WebSearch
FF SelectedSearchEngine: Yahoo! Search
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF Keyword.URL:
FF DefaultSearchUrl: hxxp://websearch.allsearches.info/?pid=3521&r=2014/10/09&hid=4176657213035267658&lg=EN&cc=CZ&unqvl=64&l=1&q=
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF SearchEngineOrder.1,S: WebSearch
FF DefaultSearchEngine,S: WebSearch
FF SelectedSearchEngine,S: WebSearch
FF NewTab: C:\ProgramData\caMyciloPs\ff.NT
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @qq.com/npAndroidAssistant -> C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3198\npQQPhoneManagerExt.dll [2014-05-30] (腾讯公司)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-26] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll [2014-12-26] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=0.9.9 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2009-03-31] (the VideoLAN Team)
FF user.js: detected! => C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\user.js [2014-10-05]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\findit.xml [2016-01-17]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\firmycz.xml [2014-10-05]
FF SearchPlugin: C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\searchplugins\zbocz.xml [2014-10-05]
FF Extension: No Name - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [not found]
FF Extension: No Name - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\extensions\sonnypenn@aol.com [not found]
FF Extension: WinToFlash Suggestor - C:\Users\Hanzka\AppData\Roaming\Mozilla\Firefox\Profiles\5kkqyohz.default\Extensions\{285ACFBB-8E53-4feb-90E6-F02A128927F3}.xpi [2012-05-25] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-01-17]
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://feed.wiki-search.me/?st=ds&query={searchTerms}
CHR DefaultSearchKeyword: Default -> Wiki Search.me
CHR Profile: C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-04]
CHR Extension: (WinToFlash Suggestor) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\acaoakiamfeidcmgooclgeleejkbaecf [2015-04-05] [UpdateUrl: hxxp://wintoflashsuggestor.net/update/updatecheckchrome-10045.xml] <==== ATTENTION
CHR Extension: (Dokumenty Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-04]
CHR Extension: (Disk Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2016-01-17]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-01-17]
CHR Extension: (YouTube) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28]
CHR Extension: (Vyhledávání Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Tabulky Google) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-04]
CHR Extension: (AdBlock) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-17]
CHR Extension: (Avast Online Security) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-01-18]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-15]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2016-01-17]
CHR Extension: (Mahjong Zahrady) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfekddiiamgblmgoodjgkfmkehnepljb [2015-12-21]
CHR Extension: (Gmail) - C:\Users\Hanzka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR HKLM-x32\...\Chrome\Extension: [acaoakiamfeidcmgooclgeleejkbaecf] - C:\Program Files (x86)\WinToFlash Suggestor\WinToFlashSuggestor.crx [2012-05-25]
CHR HKLM-x32\...\Chrome\Extension: [fcgnigmofekcllgbiejhmigggmgehkip] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-01-17]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2016-01-17] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109520 2016-01-17] (AVAST Software)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [619776 2014-12-24] (Lenovo)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [289256 2015-12-02] (McAfee, Inc.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2104840 2015-12-20] (Electronic Arts)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S2 QQPCRTP; "C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\QQPCRtp.exe" -r [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2016-01-17] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2016-01-17] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2016-01-17] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [466400 2016-01-17] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2016-01-17] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2016-01-17] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2016-01-17] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2016-01-17] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2016-01-17] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2016-01-17] (AVAST Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-10-05] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 TSSKX64; C:\Windows\System32\drivers\tsskx64.sys [45368 2015-12-28] (电脑管家)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S1 QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\QMUdisk64.sys [X]
S1 softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\softaal64.sys [X]
S1 TsDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\TsDefenseBT64.sys [X]
S2 tsnethlpx64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.3.17202.219\TsNetHlpX64.sys [X]
S3 usbbus; system32\DRIVERS\lgx64bus.sys [X]
S3 UsbDiag; system32\DRIVERS\lgx64diag.sys [X]
S3 USBModem; system32\DRIVERS\lgx64modem.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-18 16:36 - 2016-01-18 16:37 - 00019025 _____ C:\Users\Hanzka\Desktop\FRST.txt
2016-01-18 16:36 - 2016-01-18 16:36 - 00000000 ____D C:\FRST
2016-01-18 16:34 - 2016-01-18 16:34 - 02370560 _____ (Farbar) C:\Users\Hanzka\Desktop\FRST64.exe
2016-01-18 16:34 - 2016-01-18 16:34 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Desktop\FRSTLauncher.exe
2016-01-18 16:32 - 2016-01-18 16:32 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Downloads\Nepotvrzeno 8292.crdownload
2016-01-18 16:32 - 2016-01-18 16:32 - 00112640 _____ (forum.viry.cz) C:\Users\Hanzka\Downloads\Nepotvrzeno 431638.crdownload
2016-01-18 15:42 - 2012-11-29 23:27 - 00000000 ____D C:\Users\Hanzka\Downloads\Ableton Live 8.2.2 (CRACKED) [theLEAK]
2016-01-18 01:49 - 2016-01-18 03:34 - 1765020148 _____ C:\Users\Hanzka\Downloads\Ableton-Live-8.2.2-(CRACKED)-[theLEAK].rar
2016-01-17 23:52 - 2016-01-17 23:52 - 00003034 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1453071148
2016-01-17 23:52 - 2016-01-17 23:52 - 00001037 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-01-17 23:52 - 2016-01-17 23:52 - 00001037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-01-17 23:51 - 2016-01-17 23:50 - 00028144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2016-01-17 23:51 - 2016-01-17 23:45 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-01-17 23:48 - 2016-01-17 23:48 - 00001922 _____ C:\Users\Public\Desktop\Avast Premier.lnk
2016-01-17 23:48 - 2016-01-17 23:48 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\AVAST Software
2016-01-17 23:48 - 2016-01-17 23:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-01-17 23:46 - 2016-01-17 23:51 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-01-17 23:46 - 2016-01-17 23:46 - 00451040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2016-01-17 23:46 - 2016-01-17 23:46 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2016-01-17 23:46 - 2016-01-17 23:46 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
2016-01-17 23:46 - 2016-01-17 23:46 - 00000000 ____D C:\Program Files\Common Files\AV
2016-01-17 23:46 - 2016-01-17 23:45 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2016-01-17 23:46 - 2016-01-17 23:45 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2016-01-17 23:45 - 2016-01-17 23:45 - 00466400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2016-01-17 23:45 - 2016-01-17 23:45 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2016-01-17 23:44 - 2016-01-17 23:50 - 00000000 ____D C:\Program Files\AVAST Software
2016-01-17 23:44 - 2016-01-17 23:44 - 05037024 _____ (AVAST Software) C:\Users\Hanzka\Downloads\avast_premier_antivirus_setup_online.exe
2016-01-17 23:40 - 2016-01-18 00:17 - 00000000 ____D C:\ProgramData\caMyciloP
2016-01-17 23:40 - 2016-01-17 23:41 - 00000000 ____D C:\ProgramData\caMyciloPs
2016-01-17 23:38 - 2016-01-17 23:38 - 00290880 _____ C:\Windows\Minidump\011716-50528-01.dmp
2016-01-17 23:37 - 2016-01-17 23:37 - 629821633 _____ C:\Windows\MEMORY.DMP
2016-01-17 21:42 - 2016-01-17 21:42 - 00003096 _____ C:\Windows\System32\Tasks\{834FB3E9-7287-47C0-ABBD-005ED353C89F}
2016-01-17 21:33 - 2016-01-17 21:33 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Apowersoft
2016-01-17 21:33 - 2016-01-17 21:33 - 00000000 ____D C:\ProgramData\Apowersoft
2016-01-17 21:32 - 2016-01-17 21:34 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Apowersoft
2016-01-17 21:22 - 2016-01-17 21:22 - 00003562 _____ C:\Windows\System32\Tasks\{0D48CCDF-75F9-438D-A022-83E470529879}
2016-01-17 17:33 - 2016-01-17 17:33 - 00005120 _____ C:\Users\Hanzka\AppData\Roaming\GiftBag.db
2016-01-17 17:29 - 2016-01-17 17:29 - 00000000 ____D C:\Program Files (x86)\t_201601171729
2016-01-17 07:18 - 2016-01-17 07:18 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\vstsaxi
2016-01-17 06:17 - 2016-01-17 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-01-17 06:02 - 2016-01-17 06:14 - 00000000 ____D C:\Users\Hanzka\Documents\Ableton
2016-01-17 06:00 - 2016-01-18 16:08 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Ableton
2016-01-17 05:57 - 2016-01-17 23:07 - 00000000 ____D C:\ProgramData\Ableton
2016-01-17 05:57 - 2016-01-17 05:57 - 00000881 _____ C:\Users\Hanzka\Desktop\Ableton Live 9 Trial.lnk
2016-01-17 05:39 - 2016-01-17 23:40 - 00002397 _____ C:\Windows\SysWOW64\findit.xml
2016-01-17 05:39 - 2016-01-17 08:39 - 00000000 ____D C:\Program Files\cmdidx
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\ProgramData\Medlights
2016-01-17 05:39 - 2016-01-17 05:39 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-01-17 05:38 - 2016-01-18 00:17 - 00000000 ____D C:\ProgramData\Medlight
2016-01-17 05:27 - 2016-01-17 05:27 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\SimpleFiles
2016-01-17 05:16 - 2016-01-17 05:16 - 00000000 ____D C:\ProgramData\TXQMPC
2016-01-17 05:15 - 2016-01-17 17:45 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\腾讯软件
2016-01-17 05:15 - 2016-01-17 17:29 - 00087864 _____ (电脑管家) C:\Windows\system32\Drivers\TFsFltX64.sys
2016-01-17 05:15 - 2016-01-17 05:15 - 00000000 ____D C:\Program Files\Common Files\Tencent
2016-01-17 05:15 - 2015-12-28 16:34 - 00045368 _____ (电脑管家) C:\Windows\system32\Drivers\TSSKX64.sys
2016-01-17 05:14 - 2016-01-17 05:38 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Tencent
2016-01-17 05:14 - 2016-01-17 05:30 - 00000000 ____D C:\ProgramData\Tencent
2016-01-17 05:14 - 2016-01-17 05:14 - 00000000 ____D C:\Program Files (x86)\Tencent
2016-01-17 05:12 - 2016-01-17 05:12 - 00000000 ____D C:\Program Files (x86)\t_201601170512
2016-01-17 05:11 - 2016-01-17 07:30 - 00000000 ____D C:\Program Files (x86)\Seznam.cz
2016-01-17 05:11 - 2016-01-17 05:12 - 00000000 ____D C:\Program Files (x86)\MTV20151125
2016-01-17 05:11 - 2016-01-17 05:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ĂŔÍĽäŻŔŔ
2016-01-17 04:44 - 2016-01-17 05:18 - 00002568 _____ C:\Users\Hanzka\Documents\Register ACID Pro.htm
2016-01-17 04:42 - 2016-01-17 04:42 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Sony
2016-01-17 04:37 - 2016-01-17 04:37 - 00000000 ____D C:\Program Files (x86)\Sony Setup
2016-01-17 04:32 - 2016-01-17 04:38 - 701280372 _____ C:\Users\Hanzka\Downloads\ableton_live_trial_9-1-1_32.zip
2016-01-17 04:07 - 2016-01-17 04:07 - 00000394 _____ C:\Users\Hanzka\Documents\mm.ilcontrol
2015-12-21 21:18 - 2015-12-21 21:18 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-21 14:43 - 2012-02-15 14:02 - 00000000 ____D C:\Users\Hanzka\Downloads\AudioRealism_Bass_Line_VSTi_v2.5.0
2015-12-21 14:42 - 2015-12-21 14:42 - 00000000 ____D C:\Users\Hanzka\Downloads\Nová složka
2015-12-20 16:29 - 2015-12-20 16:37 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Origin
2015-12-20 16:29 - 2015-12-20 16:29 - 00000000 ____D C:\Users\Hanzka\AppData\Local\Origin
2015-12-20 16:27 - 2015-12-20 16:39 - 00000000 ____D C:\ProgramData\Origin
2015-12-20 16:27 - 2015-12-20 16:27 - 00000983 _____ C:\Users\Hanzka\Documents\Origin.lnk
2015-12-20 16:27 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-12-20 16:27 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-12-20 16:26 - 2015-12-20 16:29 - 00000000 ____D C:\Program Files (x86)\Origin
2015-12-20 16:26 - 2015-12-20 16:27 - 00000000 ____D C:\ProgramData\Package Cache
2015-12-20 01:00 - 2015-12-21 14:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioRealism Bass Line 2
2015-12-20 01:00 - 2015-12-20 01:00 - 00000000 ____D C:\Users\Hanzka\Documents\AudioRealism
2015-12-20 00:56 - 2015-12-20 00:56 - 00000000 ____D C:\Users\Hanzka\Downloads\Install_ABL2_WIN64
2015-12-19 20:57 - 2015-12-20 16:31 - 00000192 _____ C:\Users\Hanzka\Documents\hesla.txt
2015-12-19 03:00 - 2015-12-19 03:00 - 00000000 ____D C:\Users\Hanzka\Documents\Tom_hp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-18 16:36 - 2009-07-14 04:20 - 00000000 ____D C:\Windows
2016-01-18 16:23 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-01-18 16:23 - 2009-07-14 05:45 - 00014016 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-01-18 16:21 - 2015-10-12 19:26 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-18 16:20 - 2009-07-14 16:18 - 00668376 _____ C:\Windows\system32\perfh005.dat
2016-01-18 16:20 - 2009-07-14 16:18 - 00141004 _____ C:\Windows\system32\perfc005.dat
2016-01-18 16:20 - 2009-07-14 06:13 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2016-01-18 16:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
2016-01-18 16:16 - 2014-12-26 12:45 - 00000948 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-18 16:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-18 15:50 - 2014-12-26 12:45 - 00000952 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-18 00:19 - 2014-10-08 22:18 - 00000000 ____D C:\ProgramData\NNExtCoeUp
2016-01-17 23:51 - 2014-10-05 03:20 - 00000000 ____D C:\ProgramData\AVAST Software
2016-01-17 23:41 - 2014-12-26 12:46 - 00002271 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-17 23:41 - 2014-10-02 13:03 - 00001459 _____ C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-17 23:38 - 2014-10-08 22:08 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-01-17 23:38 - 2014-10-06 00:13 - 00000000 ____D C:\Windows\Minidump
2016-01-17 23:37 - 2009-07-14 05:45 - 00278568 _____ C:\Windows\system32\FNTCACHE.DAT
2016-01-17 21:47 - 2014-10-05 23:35 - 00000000 ____D C:\Program Files (x86)\Image-Line
2016-01-17 21:41 - 2014-10-13 14:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-01-17 21:41 - 2014-10-02 22:44 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2016-01-17 21:40 - 2015-10-12 21:10 - 00000000 ____D C:\Program Files (x86)\Winamp
2016-01-17 21:40 - 2014-10-13 14:16 - 00000000 ____D C:\Program Files (x86)\VstPlugins
2016-01-17 07:31 - 2014-10-05 03:39 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\Seznam.cz
2016-01-17 07:16 - 2014-10-02 15:27 - 00059104 _____ C:\Users\Hanzka\AppData\Local\GDIPFONTCACHEV1.DAT
2016-01-17 05:18 - 2015-10-21 18:21 - 00020522 _____ C:\ProgramData\svchost.exe.tmp
2016-01-17 01:59 - 2015-07-15 00:14 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-01-14 07:13 - 2014-10-06 16:50 - 00003848 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1412610607
2016-01-14 07:13 - 2014-10-06 16:50 - 00000000 ____D C:\Program Files (x86)\Opera
2016-01-05 05:56 - 2014-10-26 22:47 - 00000000 ____D C:\Users\Hanzka\AppData\Roaming\dvdcss
2016-01-04 18:09 - 2015-03-06 20:34 - 00000000 ____D C:\Users\Hanzka\Documents\hlasky
2016-01-03 19:23 - 2015-10-12 19:26 - 00003852 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-01-03 19:23 - 2014-10-05 21:08 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-01-03 19:23 - 2014-10-05 21:08 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-12-31 11:17 - 2014-10-02 13:00 - 00000000 ____D C:\Users\Hanzka
2015-12-29 11:22 - 2015-07-15 00:14 - 00003956 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
==================== Files in the root of some directories =======
2016-01-17 17:33 - 2016-01-17 17:33 - 0005120 _____ () C:\Users\Hanzka\AppData\Roaming\GiftBag.db
2014-10-08 22:10 - 2014-10-08 22:10 - 0000323 _____ () C:\Users\Hanzka\AppData\Roaming\LiveSupport.exe_log.txt
2014-10-08 22:10 - 2014-10-08 22:15 - 0000092 _____ () C:\Users\Hanzka\AppData\Roaming\regsvr32.exe_log.txt
2014-10-05 03:48 - 2014-10-05 03:48 - 0225280 _____ (Propellerhead Software AB) C:\Users\Hanzka\AppData\Roaming\Rewire.dll
2014-10-05 03:48 - 2014-10-05 03:48 - 0233472 _____ (Propellerhead Software AB) C:\Users\Hanzka\AppData\Roaming\REX Shared Library.dll
2015-10-21 18:21 - 2016-01-17 05:18 - 0020522 _____ () C:\ProgramData\svchost.exe.tmp
Files to move or delete:
====================
C:\Users\Hanzka\FL Studio VSTi (Multi).dll
C:\Users\Hanzka\FL Studio VSTi.dll
Some files in TEMP:
====================
C:\Users\Hanzka\AppData\Local\Temp\01d363ca.exe
C:\Users\Hanzka\AppData\Local\Temp\7z938.exe
C:\Users\Hanzka\AppData\Local\Temp\Ableton Swapper.exe
C:\Users\Hanzka\AppData\Local\Temp\amt_omniboxes.exe
C:\Users\Hanzka\AppData\Local\Temp\AskPIP_FF_.exe
C:\Users\Hanzka\AppData\Local\Temp\deckadance_install.exe
C:\Users\Hanzka\AppData\Local\Temp\DriverSupport.exe
C:\Users\Hanzka\AppData\Local\Temp\drvprosetup.exe
C:\Users\Hanzka\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Hanzka\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Hanzka\AppData\Local\Temp\findamo.exe
C:\Users\Hanzka\AppData\Local\Temp\GC_PCTOOLS.exe
C:\Users\Hanzka\AppData\Local\Temp\listicka-partner-13415-1.1.2-offline.exe
C:\Users\Hanzka\AppData\Local\Temp\mslog.dll
C:\Users\Hanzka\AppData\Local\Temp\msxml6-KB927977-enu-x86.exe
C:\Users\Hanzka\AppData\Local\Temp\nircmd.exe
C:\Users\Hanzka\AppData\Local\Temp\nsm1BA7.exe
C:\Users\Hanzka\AppData\Local\Temp\ochelper.exe
C:\Users\Hanzka\AppData\Local\Temp\optprosetup.exe
C:\Users\Hanzka\AppData\Local\Temp\PCMgr_Setup_11_3_17202_219.exe
C:\Users\Hanzka\AppData\Local\Temp\pcspeedup.exe
C:\Users\Hanzka\AppData\Local\Temp\qqpcmgr_v10.11.16575.227_8881436_Silence.exe
C:\Users\Hanzka\AppData\Local\Temp\rar.exe
C:\Users\Hanzka\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Hanzka\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Hanzka\AppData\Local\Temp\somoto_chrome.exe
C:\Users\Hanzka\AppData\Local\Temp\Tinyxml2.dll
C:\Users\Hanzka\AppData\Local\Temp\tmp4F17.tmp.exe
C:\Users\Hanzka\AppData\Local\Temp\utt69F7.tmp.exe
C:\Users\Hanzka\AppData\Local\Temp\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe
C:\Users\Hanzka\AppData\Local\Temp\~6080.exe
C:\Users\Hanzka\AppData\Local\Temp\~662B.exe
C:\Users\Hanzka\AppData\Local\Temp\~B3CF.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_20_0_0_267_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: avast! Antivirus (Enabled - Out of date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Out of date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Hanzka\Desktop" je 2 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================