Vir z facebook chatu
Napsal: 21 dub 2016 17:29
Ahoj potrebuju pomoc klikl jsem na video co mi prislo na fb do zpravy a mam to plne viru prosim o pomoc.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-12-2015
Ran by Pierre (administrator) on NERO (21-04-2016 18:27:09)
Running from C:\Documents and Settings\Pierre\Plocha
Loaded Profiles: Pierre (Available Profiles: Pierre)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
() C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
() C:\Program Files\EaseUS\TrayPopup\TrayTipAgent.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager\main\MiPhoneHelper.exe
() C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\bin\szndesktop.exe
() C:\Program Files\EaseUS\Todo Backup\bin\TodoBackupService.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\Update\SmartShareTray.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\DMS\SmartShareDMS.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\DMR\SmartShareDMR.exe
(Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD.EXE
() C:\Documents and Settings\All Users\Data aplikací\CloudPrinter\CloudPrinter.exe
(Search Module Ltd.) C:\Program Files\Common Files\Doobzo\GSUpdate\smu.exe
() C:\Program Files\badu\uc.exe
( ) C:\Program Files\badu\Bind.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Launch LCDMon] => C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [1687824 2007-07-17] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] => C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [2094352 2007-07-17] (Logitech Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [LG Smart Share] => C:\Program Files\LG Software\LG Smart Share\SmartShareStartXP.exe [134744 2013-03-25] (LG Electronics Inc.)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [366904 2015-07-23] (Power Software Ltd)
HKLM\...\Run: [EaseUS EPM tray] => C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\EpmNews.exe [2089056 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe [255072 2014-11-18] ()
HKLM\...\Run: [EaseUS TB Tray Agent] => C:\Program Files\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2014-12-15] ()
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2591888 2015-09-14] ()
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-27] (NVIDIA Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM\...\Run: [SpyHunter Security Suite] => C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [7252864 2016-04-21] (Enigma Software Group USA, LLC.)
HKLM\...\Run: [22] => C:\Documents and Settings\Pierre\Local Settings\temp\22.exe [3680768 2016-04-21] () <===== ATTENTION
HKLM\...\Run: [apphide] => C:\Program Files\badu\uc.exe [245829 2016-04-03] ()
HKLM\...\Run: [pcmgr] => C:\Program Files\badu\Uninst.exe
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [4556048 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [cz.seznam.software.autoupdate] => C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [cz.seznam.software.szndesktop] => C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [GoogleChromeAutoLaunch_BD17503A2D8EC1E93944F64D6130C39D] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [MiPhoneManager] => C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [GSplay.exe] => GSPlay.exe REG_EXPAND_SZ C:\Pierre\Download\GSplay\GSplay.exe
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [svchost0] => C:\Program Files\UCBrowser\Application\UUC0789.exe [69632 2016-04-21] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [apphide] => C:\Program Files\badu\uc.exe [245829 2016-04-03] ()
AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\DATAAP~1\Quoteex\Inchnix.dll => C:\Documents and Settings\All Users\Data aplikací\Quoteex\Inchnix.dll [257536 2016-04-21] ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\CineForm Status.lnk [2015-09-16]
ShortcutTarget: CineForm Status.lnk -> C:\Program Files\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{95358A7A-F515-4188-B822-D6E5B12114F4}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sTRm4aAJLt4LIUJzEgiY6I7AfIcSaYAcznIuZ7WXER1-3PQg_ZIxhBtQZYMA4H5qC5qY6_AeLklZU5S-Uu
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sTRm4aAJLt4LIUJzEgiY6I7AfIcSaYAcznIuZ7WXER1-3PQg_ZIxhBtQZYMA4H5qC5qY6_AeLklZU5S-Uu
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ie
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-19 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {0FDD15E1-D10C-4195-8EFB-87052BFC6870} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
BHO: TSearch -> {6E727987-C8EA-44DA-8749-310C0FBE3C3E} -> \Torrent Search\IEEF\qcZtGKqHlUOe.dll => No File
Toolbar: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1454471165-1326574676-839522115-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-03-05] [not signed]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ch
CHR StartupUrls: Default -> "hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ch"
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?site=shyos&prd=set_ch&q={searchTerms}&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-19]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-23]
CHR Extension: (Disk Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (YouTube) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Tabulky Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-19]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (Terapaper) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hkibjmfcciicdoofeljjmffoekkcnjnm [2016-04-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-12]
CHR Extension: (Gmail) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-23]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CloudPrinter; C:\Documents and Settings\All Users\Data aplikací\\CloudPrinter\\CloudPrinter.exe [1027584 2016-04-21] () [File not signed]
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1030928 2015-02-27] (Disc Soft Ltd)
R2 EaseUS Agent; C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [36904 2015-08-01] (CHENGDU YIWO Tech Development Co., Ltd)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [595968 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [642520 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-27] (NVIDIA Corporation)
S2 Quoteex; C:\Documents and Settings\All Users\Data aplikací\\Quoteex\\Quoteex.exe [1027584 2016-04-21] () [File not signed]
R2 SMUpd; C:\Program Files\Common Files\Doobzo\GSUpdate\smu.exe [1577984 2016-04-19] (Search Module Ltd.) [File not signed]
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [784256 2016-04-21] (Enigma Software Group USA, LLC.)
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [814064 2015-12-22] (Tunngle.net GmbH)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R3 dtlitescsibus; C:\WINDOWS\System32\DRIVERS\dtlitescsibus.sys [25104 2015-06-21] (Disc Soft Ltd)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [14944 2014-11-18] ()
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2016-04-21] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2016-04-21] ()
R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [52008 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [40744 2014-12-15] ()
R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [14888 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [188328 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10208 2014-11-18] ()
R3 ip100xp; C:\WINDOWS\System32\DRIVERS\ipfnd51.sys [26752 2010-11-23] (IC Plus Corp. ) [File not signed]
R3 MEI; C:\WINDOWS\System32\DRIVERS\HECI.sys [56280 2013-09-16] (Intel Corporation)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
U0 MPCBase; C:\WINDOWS\System32\drivers\MPCBase.sys [29032 2016-04-21] (DotC United Inc)
R1 MPCKpt; C:\WINDOWS\System32\DRIVERS\MPCKpt.sys [53992 2016-04-21] (DotC United Inc)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [136624 2015-09-14] (NVIDIA Corporation)
R1 SCDEmu; C:\WINDOWS\system32\Drivers\SCDEmu.sys [114304 2015-07-23] (Power Software Ltd)
R3 SMUpdd; C:\Program Files\Common Files\Doobzo\GSUpdate\smw.sys [25600 2016-04-19] () [File not signed]
R3 tap0901t; C:\WINDOWS\System32\DRIVERS\tap0901t.sys [43568 2015-12-21] (Tunngle.net)
U1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [71040 2016-03-28] (Huorong Borui (Beijing) Technology Co., Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S4 IntelIde; no ImagePath
S3 MSICDSetup; \??\D:\CDriver.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-21 18:26 - 2016-04-21 18:26 - 00000446 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-21 18:26 - 2016-04-21 18:26 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\UCBrowser
2016-04-21 18:26 - 2016-03-28 14:46 - 00071040 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-21 18:25 - 2016-04-21 18:26 - 00000000 ____D C:\Program Files\UCBrowser
2016-04-21 18:22 - 2016-04-21 18:22 - 00000000 ____D C:\Program Files\badu
2016-04-21 18:21 - 2016-04-21 18:22 - 00000952 _____ C:\WINDOWS\Tasks\SMW_UpdateTask_Time_333533323338323033352d3437415a556c2a3223346c41.job
2016-04-21 18:21 - 2016-04-21 18:21 - 00356864 _____ C:\Documents and Settings\All Users\Data aplikací\smp2.exe
2016-04-21 18:21 - 2016-04-21 18:21 - 00000881 _____ C:\Documents and Settings\Pierre\Plocha\Continue installation .lnk
2016-04-21 18:21 - 2016-04-21 18:21 - 00000652 _____ C:\WINDOWS\Tasks\SMW_P.job
2016-04-21 18:21 - 2016-04-21 18:21 - 00000000 ____D C:\Program Files\Common Files\Doobzo
2016-04-21 18:21 - 2016-04-21 18:21 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SearchModule
2016-04-21 18:20 - 2016-04-21 18:20 - 00053992 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.sys
2016-04-21 18:20 - 2016-04-21 18:20 - 00029032 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCBase.sys
2016-04-21 18:20 - 2016-04-21 18:20 - 00000000 ____D C:\Program Files\MPC Cleaner
2016-04-21 18:19 - 2016-04-21 18:19 - 00002385 _____ C:\WINDOWS\system32\findit.xml
2016-04-21 18:19 - 2016-04-21 18:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Quoteexs
2016-04-21 18:18 - 2016-04-21 18:20 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Quoteex
2016-04-21 18:18 - 2016-04-21 18:18 - 06494208 _____ C:\Documents and Settings\Pierre\Data aplikací\agent.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 01626777 _____ C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 01027584 _____ C:\Documents and Settings\Pierre\Data aplikací\Sanzap.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 01027584 _____ C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 00848437 _____ C:\Documents and Settings\Pierre\Data aplikací\Silverlight.bin
2016-04-21 18:18 - 2016-04-21 18:18 - 00127488 _____ C:\Documents and Settings\Pierre\Data aplikací\Installer.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00126464 _____ C:\Documents and Settings\Pierre\Data aplikací\noah.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00126464 _____ C:\Documents and Settings\Pierre\Data aplikací\lobby.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00079662 _____ C:\Documents and Settings\Pierre\Data aplikací\inst.lat
2016-04-21 18:18 - 2016-04-21 18:18 - 00072717 _____ C:\Documents and Settings\Pierre\Data aplikací\Sanzap.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 00065568 _____ C:\Documents and Settings\Pierre\Data aplikací\Config.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00054272 _____ C:\Documents and Settings\Pierre\Data aplikací\ApplicationHosting.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00018432 _____ C:\Documents and Settings\Pierre\Data aplikací\Main.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00015840 _____ C:\Documents and Settings\Pierre\Data aplikací\InstallationConfiguration.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00005568 _____ C:\Documents and Settings\Pierre\Data aplikací\md.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00000000 ____D C:\Program Files\Common Files\Transrandax
2016-04-21 18:18 - 2016-04-21 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\CloudPrinter
2016-04-21 18:12 - 2016-04-21 18:12 - 00000248 _____ C:\WINDOWS\Tasks\Update Service for Torrent Search.job
2016-04-21 18:12 - 2016-04-21 18:12 - 00000000 ____D C:\Program Files\Torrent Search
2016-04-21 17:44 - 2016-04-21 17:44 - 00090112 _____ C:\WINDOWS\Minidump\Mini042116-01.dmp
2016-04-21 17:39 - 2016-04-21 17:39 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Enigma Software Group
2016-04-21 17:38 - 2016-04-21 17:38 - 00000000 ____D C:\sh4ldr
2016-04-21 17:37 - 2016-04-21 17:37 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-04-21 17:37 - 2016-04-21 17:37 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-04-18 21:06 - 2016-04-18 21:06 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Data aplikací\Google
2016-04-08 11:03 - 2016-04-08 11:03 - 05934784 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-03-29 23:16 - 2016-04-21 10:18 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\EurekaLog
2016-03-29 14:31 - 2016-03-29 14:31 - 01463253 _____ C:\Documents and Settings\Pierre\Plocha\Dane 2016 5132550_2015_d298ba1310.pdf
2016-03-29 13:59 - 2016-03-29 13:59 - 00237486 _____ C:\Documents and Settings\Pierre\Plocha\A160302_VEN_005_DANE_2015_D.XLSX
2016-03-26 14:02 - 2016-03-26 14:02 - 00036864 _____ C:\Documents and Settings\Pierre\Plocha\1458856945_e3dd35254fffe456a5472dae15fd9e16.xls
2016-03-25 02:53 - 2016-03-25 02:53 - 00047166 _____ C:\Documents and Settings\Pierre\Dokumenty\Agents of SHIELD S03E13 - Parting Shot (AVS).srt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-21 18:27 - 2015-12-30 20:47 - 00027017 _____ C:\Documents and Settings\Pierre\Plocha\FRST.txt
2016-04-21 18:27 - 2015-12-30 20:47 - 00000000 ____D C:\FRST
2016-04-21 18:27 - 2015-07-13 00:36 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\temp
2016-04-21 18:26 - 2015-12-30 20:46 - 00029696 _____ C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MSGBOX.EXE
2016-04-21 18:26 - 2015-02-25 22:15 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-04-21 18:26 - 2015-02-25 22:15 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-04-21 18:26 - 2015-02-25 21:47 - 00000000 ___HD C:\Documents and Settings\Pierre\Local Settings\Data aplikací
2016-04-21 18:26 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre\Plocha
2016-04-21 18:25 - 2015-09-17 20:10 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-21 18:24 - 2015-09-04 12:12 - 00001819 _____ C:\Documents and Settings\Default User\Nabídka Start\Programy\Google Chrome.lnk
2016-04-21 18:24 - 2015-09-04 12:12 - 00001813 _____ C:\Documents and Settings\Default User\Plocha\Google Chrome.lnk
2016-04-21 18:22 - 2015-02-25 22:13 - 00000000 ____D C:\Pierre
2016-04-21 18:21 - 2015-02-26 00:41 - 00009328 _____ C:\WINDOWS\system32\nvAppTimestamps
2016-04-21 18:21 - 2015-02-25 22:15 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-04-21 18:20 - 2015-04-03 10:13 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Mozilla
2016-04-21 18:18 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací
2016-04-21 18:03 - 2015-06-19 00:32 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-21 17:51 - 2015-02-25 21:47 - 00001599 _____ C:\Documents and Settings\Pierre\Nabídka Start\Programy\Vzdálená pomoc.lnk
2016-04-21 17:50 - 2015-03-01 10:42 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz
2016-04-21 17:50 - 2015-02-25 21:36 - 00001599 _____ C:\Documents and Settings\Default User\Nabídka Start\Programy\Vzdálená pomoc.lnk
2016-04-21 17:50 - 2015-02-25 21:36 - 00001507 _____ C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2016-04-21 17:49 - 2015-02-25 22:16 - 01184620 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-21 17:49 - 2004-08-18 14:00 - 00489962 _____ C:\WINDOWS\system32\perfh005.dat
2016-04-21 17:49 - 2004-08-18 14:00 - 00098506 _____ C:\WINDOWS\system32\perfc005.dat
2016-04-21 17:46 - 2015-02-26 00:32 - 01606500 _____ C:\WINDOWS\system32\nvdrsdb0.bin
2016-04-21 17:46 - 2015-02-26 00:32 - 00000001 _____ C:\WINDOWS\system32\nvdrssel.bin
2016-04-21 17:45 - 2015-09-17 20:09 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-21 17:45 - 2015-09-04 12:06 - 00001054 _____ C:\WINDOWS\Tasks\ExObslI9P8NNjD3RrGI0HIktb.job
2016-04-21 17:45 - 2015-02-25 22:09 - 00000000 ____D C:\WINDOWS
2016-04-21 17:45 - 2004-08-18 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-04-21 17:44 - 2015-09-04 12:10 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-21 17:44 - 2015-02-25 21:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-21 17:39 - 2015-02-25 22:09 - 00000000 ___HD C:\WINDOWS\inf
2016-04-21 17:38 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre
2016-04-21 17:34 - 2015-02-26 00:32 - 01606500 _____ C:\WINDOWS\system32\nvdrsdb1.bin
2016-04-21 17:31 - 2015-03-01 11:51 - 00211826 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2016-04-21 17:31 - 2015-02-25 21:47 - 00000178 ___SH C:\Documents and Settings\Pierre\ntuser.ini
2016-04-21 17:31 - 2015-02-25 21:40 - 00032460 _____ C:\WINDOWS\SchedLgU.Txt
2016-04-21 17:30 - 2015-07-12 23:12 - 00000000 ____D C:\AdwCleaner
2016-04-21 17:30 - 2015-02-25 21:47 - 00000000 ___RD C:\Documents and Settings\Pierre\Nabídka Start\Programy
2016-04-21 17:30 - 2015-02-25 21:47 - 00000000 ___RD C:\Documents and Settings\Pierre\Dokumenty
2016-04-21 17:23 - 2015-09-15 23:28 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\JDownloader v2.0
2016-04-21 10:19 - 2016-02-10 18:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Tunngle
2016-04-20 01:05 - 2016-02-10 17:27 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Tunngle
2016-04-18 21:06 - 2015-02-25 22:15 - 00000000 ___HD C:\Documents and Settings\Default User\Local Settings\Data aplikací
2016-04-14 11:15 - 2015-02-26 14:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-14 11:10 - 2015-02-26 14:25 - 132539272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-13 15:34 - 2015-02-28 22:27 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\vlc
2016-04-13 02:06 - 2015-02-25 23:56 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-04-08 11:03 - 2015-06-19 00:32 - 00797376 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-04-08 11:03 - 2015-06-19 00:32 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-04-07 20:48 - 2015-02-26 00:54 - 00000000 ____D C:\Program Files\Counter Strike 1.6
2016-04-07 20:48 - 2015-02-26 00:51 - 00000000 ____D C:\Documents and Settings\Pierre\GSplay
2016-04-06 00:05 - 2015-10-04 08:35 - 00001221 _____ C:\Documents and Settings\Pierre\Plocha\MiPCSuite.lnk
2016-04-06 00:05 - 2015-10-04 08:35 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager
2016-03-29 23:16 - 2016-02-10 17:27 - 00000000 ____D C:\Program Files\Tunngle
2016-03-29 19:48 - 2015-03-01 11:51 - 01772232 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1454471165-1326574676-839522115-1003-0.dat
==================== Files in the root of some directories =======
2016-04-21 18:18 - 2016-04-21 18:18 - 6494208 _____ () C:\Documents and Settings\Pierre\Data aplikací\agent.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0054272 _____ () C:\Documents and Settings\Pierre\Data aplikací\ApplicationHosting.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0065568 _____ () C:\Documents and Settings\Pierre\Data aplikací\Config.xml
2015-08-17 15:56 - 2015-08-17 15:56 - 0000245 _____ () C:\Documents and Settings\Pierre\Data aplikací\del.bat
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Documents and Settings\Pierre\Data aplikací\ExObslI9P8NNjD3RrGI0HIktb
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Documents and Settings\Pierre\Data aplikací\ExObslI9P8NNjD3RrGI0HIktb.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 0079662 _____ () C:\Documents and Settings\Pierre\Data aplikací\inst.lat
2016-04-21 18:18 - 2016-04-21 18:18 - 0015840 _____ () C:\Documents and Settings\Pierre\Data aplikací\InstallationConfiguration.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 0127488 _____ () C:\Documents and Settings\Pierre\Data aplikací\Installer.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0126464 _____ () C:\Documents and Settings\Pierre\Data aplikací\lobby.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0018432 _____ () C:\Documents and Settings\Pierre\Data aplikací\Main.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0005568 _____ () C:\Documents and Settings\Pierre\Data aplikací\md.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 0126464 _____ () C:\Documents and Settings\Pierre\Data aplikací\noah.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 1027584 _____ () C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 1626777 _____ () C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 1027584 _____ () C:\Documents and Settings\Pierre\Data aplikací\Sanzap.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 0072717 _____ () C:\Documents and Settings\Pierre\Data aplikací\Sanzap.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 0848437 _____ () C:\Documents and Settings\Pierre\Data aplikací\Silverlight.bin
2016-04-21 18:18 - 2016-04-21 18:18 - 0032038 _____ () C:\Documents and Settings\Pierre\Data aplikací\uninstall_temp.ico
2015-06-25 19:59 - 2015-10-04 08:22 - 0009216 _____ () C:\Documents and Settings\Pierre\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-30 20:46 - 2016-04-21 18:26 - 0029696 _____ () C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MSGBOX.EXE
2016-04-21 18:21 - 2016-04-21 18:21 - 0356864 _____ () C:\Documents and Settings\All Users\Data aplikací\smp2.exe
2015-09-04 11:48 - 2015-09-04 11:48 - 0004105 _____ () C:\Documents and Settings\All Users\Data aplikací\wmzddnmb.cix
Files to move or delete:
====================
C:\Documents and Settings\Pierre\Local Settings\temp\22.exe
Some files in TEMP:
====================
C:\Documents and Settings\Pierre\Local Settings\temp\130868260149721582.exe
C:\Documents and Settings\Pierre\Local Settings\temp\13086826016440908203.exe
C:\Documents and Settings\Pierre\Local Settings\temp\22.exe
C:\Documents and Settings\Pierre\Local Settings\temp\3098.exe
C:\Documents and Settings\Pierre\Local Settings\temp\8115.exe
C:\Documents and Settings\Pierre\Local Settings\temp\8333.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Browser_V5.6.11466.7_r_4714_(Build1603281525).exe
C:\Documents and Settings\Pierre\Local Settings\temp\geeplayersetup_unfix.exe
C:\Documents and Settings\Pierre\Local Settings\temp\IQIYIsetup_l_huayukeji@kb006.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u51-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u65-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u91-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\libeay32.dll
C:\Documents and Settings\Pierre\Local Settings\temp\listicka-partner-16194-1.1.8-offline.exe
C:\Documents and Settings\Pierre\Local Settings\temp\msvcr120.dll
C:\Documents and Settings\Pierre\Local Settings\temp\pps104.exe
C:\Documents and Settings\Pierre\Local Settings\temp\proxy_vole6407598957250881067.dll
C:\Documents and Settings\Pierre\Local Settings\temp\qqpcmgr_v10.5.15816.217_70557_Silence.exe
C:\Documents and Settings\Pierre\Local Settings\temp\qqpcmgr_v11.3.17195.214_78450_Silence.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Quarantine.exe
C:\Documents and Settings\Pierre\Local Settings\temp\set.exe
C:\Documents and Settings\Pierre\Local Settings\temp\setup.exe
C:\Documents and Settings\Pierre\Local Settings\temp\setup3.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Setup__2140_il357769.exe
C:\Documents and Settings\Pierre\Local Settings\temp\sqlite-3.8.2-x86-sqlitejdbc.dll
C:\Documents and Settings\Pierre\Local Settings\temp\sqlite3.dll
C:\Documents and Settings\Pierre\Local Settings\temp\{94DF23C8-D11B-4097-914C-20448C9B66C9}.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:30-12-2015
Ran by Pierre (administrator) on NERO (21-04-2016 18:27:09)
Running from C:\Documents and Settings\Pierre\Plocha
Loaded Profiles: Pierre (Available Profiles: Pierre)
Platform: Systém Microsoft Windows XP Professional Service Pack 3 (X86) Language: Čeština
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Realtek Semiconductor Corp.) C:\WINDOWS\RTHDCPL.EXE
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
() C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe
() C:\Program Files\EaseUS\TrayPopup\TrayTipAgent.exe
(Logitech Inc.) C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
() C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager\main\MiPhoneHelper.exe
() C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\bin\szndesktop.exe
() C:\Program Files\EaseUS\Todo Backup\bin\TodoBackupService.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\Update\SmartShareTray.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\DMS\SmartShareDMS.exe
(LG Electronics Inc.) C:\Program Files\LG Software\LG Smart Share\DMR\SmartShareDMR.exe
(Ghisler Software GmbH) C:\Program Files\totalcmd\TOTALCMD.EXE
() C:\Documents and Settings\All Users\Data aplikací\CloudPrinter\CloudPrinter.exe
(Search Module Ltd.) C:\Program Files\Common Files\Doobzo\GSUpdate\smu.exe
() C:\Program Files\badu\uc.exe
( ) C:\Program Files\badu\Bind.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
(UCWeb Inc.) C:\Program Files\UCBrowser\Application\UCBrowser.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BluetoothAuthenticationAgent] => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
HKLM\...\Run: [RTHDCPL] => C:\WINDOWS\RTHDCPL.EXE [20065936 2012-06-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [Launch LCDMon] => C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe [1687824 2007-07-17] (Logitech Inc.)
HKLM\...\Run: [Launch LGDCore] => C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe [2094352 2007-07-17] (Logitech Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [LG Smart Share] => C:\Program Files\LG Software\LG Smart Share\SmartShareStartXP.exe [134744 2013-03-25] (LG Electronics Inc.)
HKLM\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [366904 2015-07-23] (Power Software Ltd)
HKLM\...\Run: [EaseUS EPM tray] => C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\EpmNews.exe [2089056 2014-11-18] (CHENGDU YIWO Tech Development Co., Ltd)
HKLM\...\Run: [EaseUS EPM Tray Agent] => C:\Program Files\EaseUS\EaseUS Partition Master 10.2\bin\TrayPopupE\TrayTipAgentE.exe [255072 2014-11-18] ()
HKLM\...\Run: [EaseUS TB Tray Agent] => C:\Program Files\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2014-12-15] ()
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [NvMediaCenter] => RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2591888 2015-09-14] ()
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2634872 2015-08-27] (NVIDIA Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM\...\Run: [SpyHunter Security Suite] => C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [7252864 2016-04-21] (Enigma Software Group USA, LLC.)
HKLM\...\Run: [22] => C:\Documents and Settings\Pierre\Local Settings\temp\22.exe [3680768 2016-04-21] () <===== ATTENTION
HKLM\...\Run: [apphide] => C:\Program Files\badu\uc.exe [245829 2016-04-03] ()
HKLM\...\Run: [pcmgr] => C:\Program Files\badu\Uninst.exe
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [4556048 2015-02-27] (Disc Soft Ltd)
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [cz.seznam.software.autoupdate] => C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [cz.seznam.software.szndesktop] => C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz\bin\wszndesktop.exe [103080 2015-05-26] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [GoogleChromeAutoLaunch_BD17503A2D8EC1E93944F64D6130C39D] => "C:\Program Files\Crossbrowse\Crossbrowse\Application\crossbrowse.exe" --no-startup-window
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [MiPhoneManager] => C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager\main\MiPhoneHelper.exe [157624 2016-03-11] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [GSplay.exe] => GSPlay.exe REG_EXPAND_SZ C:\Pierre\Download\GSplay\GSplay.exe
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [svchost0] => C:\Program Files\UCBrowser\Application\UUC0789.exe [69632 2016-04-21] ()
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\...\Run: [apphide] => C:\Program Files\badu\uc.exe [245829 2016-04-03] ()
AppInit_DLLs: C:\DOCUME~1\ALLUSE~1\DATAAP~1\Quoteex\Inchnix.dll => C:\Documents and Settings\All Users\Data aplikací\Quoteex\Inchnix.dll [257536 2016-04-21] ()
Startup: C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\CineForm Status.lnk [2015-09-16]
ShortcutTarget: CineForm Status.lnk -> C:\Program Files\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{95358A7A-F515-4188-B822-D6E5B12114F4}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sTRm4aAJLt4LIUJzEgiY6I7AfIcSaYAcznIuZ7WXER1-3PQg_ZIxhBtQZYMA4H5qC5qY6_AeLklZU5S-Uu
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sTRm4aAJLt4LIUJzEgiY6I7AfIcSaYAcznIuZ7WXER1-3PQg_ZIxhBtQZYMA4H5qC5qY6_AeLklZU5S-Uu
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ie
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
HKU\S-1-5-21-1454471165-1326574676-839522115-1003\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM -> ielnksrch URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-19 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-20 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> DefaultScope {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {0FDD15E1-D10C-4195-8EFB-87052BFC6870} URL = hxxp://www-searching.com/s.ashx?prd=opensearch&q={searchTerms}&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> {ielnksrch} URL = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0RErzyPsJ4T7k2COOv4oRHbgpZu2LUFGw9gPtHD0MXnlWN7KG6uKFJJVYhghjj_sfjiHQKJsmEQZlUtlpsqh84-5WAOcvYhVxGZS_l-ErE2V8JaLhR_RO7G_ejL5vbEMOWRkD170L_VRGPvOY&q={searchTerms}
BHO: TSearch -> {6E727987-C8EA-44DA-8749-310C0FBE3C3E} -> \Torrent Search\IEEF\qcZtGKqHlUOe.dll => No File
Toolbar: HKU\S-1-5-21-1454471165-1326574676-839522115-1003 -> &Adresa - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll [2014-02-25] (Společnost Microsoft)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_21_0_0_213.dll [2016-04-08] ()
FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1454471165-1326574676-839522115-1003: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-03-05] [not signed]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HomePage: Default -> hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ch
CHR StartupUrls: Default -> "hxxp://www-searching.com/?pid=s&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,&vp=ch&prd=set_ch"
CHR DefaultSearchURL: Default -> hxxp://www-searching.com/search.aspx?site=shyos&prd=set_ch&q={searchTerms}&s=G4Lzamobl2140BK,85deacda-0df5-4b77-ab49-6968bcd52e8a,
CHR DefaultSearchKeyword: Default -> www-searching.com
CHR DefaultSuggestURL: Default -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-19]
CHR Extension: (Dokumenty Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-23]
CHR Extension: (Disk Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (YouTube) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-01]
CHR Extension: (Vyhledávání Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Tabulky Google) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-19]
CHR Extension: (Dokumenty Google offline) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (Terapaper) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\hkibjmfcciicdoofeljjmffoekkcnjnm [2016-04-21]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-12]
CHR Extension: (Gmail) - C:\Documents and Settings\Pierre\Local Settings\Data aplikací\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-23]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CloudPrinter; C:\Documents and Settings\All Users\Data aplikací\\CloudPrinter\\CloudPrinter.exe [1027584 2016-04-21] () [File not signed]
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1030928 2015-02-27] (Disc Soft Ltd)
R2 EaseUS Agent; C:\Program Files\EaseUS\Todo Backup\bin\Agent.exe [36904 2015-08-01] (CHENGDU YIWO Tech Development Co., Ltd)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [595968 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [642520 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-08-27] (NVIDIA Corporation)
S2 Quoteex; C:\Documents and Settings\All Users\Data aplikací\\Quoteex\\Quoteex.exe [1027584 2016-04-21] () [File not signed]
R2 SMUpd; C:\Program Files\Common Files\Doobzo\GSUpdate\smu.exe [1577984 2016-04-19] (Search Module Ltd.) [File not signed]
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [784256 2016-04-21] (Enigma Software Group USA, LLC.)
S3 TunngleService; C:\Program Files\Tunngle\TnglCtrl.exe [814064 2015-12-22] (Tunngle.net GmbH)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Ambfilt; C:\WINDOWS\System32\drivers\Ambfilt.sys [1691480 2009-11-18] (Creative)
R3 dtlitescsibus; C:\WINDOWS\System32\DRIVERS\dtlitescsibus.sys [25104 2015-06-21] (Disc Soft Ltd)
S3 epmntdrv; C:\WINDOWS\system32\epmntdrv.sys [14944 2014-11-18] ()
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2016-04-21] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [19984 2016-04-21] ()
R0 EUBAKUP; C:\WINDOWS\System32\drivers\eubakup.sys [52008 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
R0 EUBKMON; C:\WINDOWS\System32\drivers\EUBKMON.sys [40744 2014-12-15] ()
R1 EUDSKACS; C:\WINDOWS\system32\drivers\eudskacs.sys [14888 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
R1 EUFDDISK; C:\WINDOWS\system32\drivers\EuFdDisk.sys [188328 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
S3 EuGdiDrv; C:\WINDOWS\system32\EuGdiDrv.sys [10208 2014-11-18] ()
R3 ip100xp; C:\WINDOWS\System32\DRIVERS\ipfnd51.sys [26752 2010-11-23] (IC Plus Corp. ) [File not signed]
R3 MEI; C:\WINDOWS\System32\DRIVERS\HECI.sys [56280 2013-09-16] (Intel Corporation)
S3 Monfilt; C:\WINDOWS\System32\drivers\Monfilt.sys [1395800 2009-11-18] (Creative Technology Ltd.)
U0 MPCBase; C:\WINDOWS\System32\drivers\MPCBase.sys [29032 2016-04-21] (DotC United Inc)
R1 MPCKpt; C:\WINDOWS\System32\DRIVERS\MPCKpt.sys [53992 2016-04-21] (DotC United Inc)
R3 NVHDA; C:\WINDOWS\System32\drivers\nvhda32.sys [136624 2015-09-14] (NVIDIA Corporation)
R1 SCDEmu; C:\WINDOWS\system32\Drivers\SCDEmu.sys [114304 2015-07-23] (Power Software Ltd)
R3 SMUpdd; C:\Program Files\Common Files\Doobzo\GSUpdate\smw.sys [25600 2016-04-19] () [File not signed]
R3 tap0901t; C:\WINDOWS\System32\DRIVERS\tap0901t.sys [43568 2015-12-21] (Tunngle.net)
U1 UCGuard; C:\WINDOWS\System32\DRIVERS\ucguard.sys [71040 2016-03-28] (Huorong Borui (Beijing) Technology Co., Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S4 IntelIde; no ImagePath
S3 MSICDSetup; \??\D:\CDriver.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-21 18:26 - 2016-04-21 18:26 - 00000446 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-21 18:26 - 2016-04-21 18:26 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\UCBrowser
2016-04-21 18:26 - 2016-03-28 14:46 - 00071040 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-21 18:25 - 2016-04-21 18:26 - 00000000 ____D C:\Program Files\UCBrowser
2016-04-21 18:22 - 2016-04-21 18:22 - 00000000 ____D C:\Program Files\badu
2016-04-21 18:21 - 2016-04-21 18:22 - 00000952 _____ C:\WINDOWS\Tasks\SMW_UpdateTask_Time_333533323338323033352d3437415a556c2a3223346c41.job
2016-04-21 18:21 - 2016-04-21 18:21 - 00356864 _____ C:\Documents and Settings\All Users\Data aplikací\smp2.exe
2016-04-21 18:21 - 2016-04-21 18:21 - 00000881 _____ C:\Documents and Settings\Pierre\Plocha\Continue installation .lnk
2016-04-21 18:21 - 2016-04-21 18:21 - 00000652 _____ C:\WINDOWS\Tasks\SMW_P.job
2016-04-21 18:21 - 2016-04-21 18:21 - 00000000 ____D C:\Program Files\Common Files\Doobzo
2016-04-21 18:21 - 2016-04-21 18:21 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\SearchModule
2016-04-21 18:20 - 2016-04-21 18:20 - 00053992 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCKpt.sys
2016-04-21 18:20 - 2016-04-21 18:20 - 00029032 _____ (DotC United Inc) C:\WINDOWS\system32\Drivers\MPCBase.sys
2016-04-21 18:20 - 2016-04-21 18:20 - 00000000 ____D C:\Program Files\MPC Cleaner
2016-04-21 18:19 - 2016-04-21 18:19 - 00002385 _____ C:\WINDOWS\system32\findit.xml
2016-04-21 18:19 - 2016-04-21 18:19 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Quoteexs
2016-04-21 18:18 - 2016-04-21 18:20 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Quoteex
2016-04-21 18:18 - 2016-04-21 18:18 - 06494208 _____ C:\Documents and Settings\Pierre\Data aplikací\agent.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 01626777 _____ C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 01027584 _____ C:\Documents and Settings\Pierre\Data aplikací\Sanzap.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 01027584 _____ C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 00848437 _____ C:\Documents and Settings\Pierre\Data aplikací\Silverlight.bin
2016-04-21 18:18 - 2016-04-21 18:18 - 00127488 _____ C:\Documents and Settings\Pierre\Data aplikací\Installer.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00126464 _____ C:\Documents and Settings\Pierre\Data aplikací\noah.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00126464 _____ C:\Documents and Settings\Pierre\Data aplikací\lobby.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00079662 _____ C:\Documents and Settings\Pierre\Data aplikací\inst.lat
2016-04-21 18:18 - 2016-04-21 18:18 - 00072717 _____ C:\Documents and Settings\Pierre\Data aplikací\Sanzap.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 00065568 _____ C:\Documents and Settings\Pierre\Data aplikací\Config.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00054272 _____ C:\Documents and Settings\Pierre\Data aplikací\ApplicationHosting.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00018432 _____ C:\Documents and Settings\Pierre\Data aplikací\Main.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 00015840 _____ C:\Documents and Settings\Pierre\Data aplikací\InstallationConfiguration.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00005568 _____ C:\Documents and Settings\Pierre\Data aplikací\md.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 00000000 ____D C:\Program Files\Common Files\Transrandax
2016-04-21 18:18 - 2016-04-21 18:18 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\CloudPrinter
2016-04-21 18:12 - 2016-04-21 18:12 - 00000248 _____ C:\WINDOWS\Tasks\Update Service for Torrent Search.job
2016-04-21 18:12 - 2016-04-21 18:12 - 00000000 ____D C:\Program Files\Torrent Search
2016-04-21 17:44 - 2016-04-21 17:44 - 00090112 _____ C:\WINDOWS\Minidump\Mini042116-01.dmp
2016-04-21 17:39 - 2016-04-21 17:39 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Enigma Software Group
2016-04-21 17:38 - 2016-04-21 17:38 - 00000000 ____D C:\sh4ldr
2016-04-21 17:37 - 2016-04-21 17:37 - 00019984 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-04-21 17:37 - 2016-04-21 17:37 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-04-18 21:06 - 2016-04-18 21:06 - 00000000 ____D C:\Documents and Settings\Default User\Local Settings\Data aplikací\Google
2016-04-08 11:03 - 2016-04-08 11:03 - 05934784 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerInstaller.exe
2016-03-29 23:16 - 2016-04-21 10:18 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\EurekaLog
2016-03-29 14:31 - 2016-03-29 14:31 - 01463253 _____ C:\Documents and Settings\Pierre\Plocha\Dane 2016 5132550_2015_d298ba1310.pdf
2016-03-29 13:59 - 2016-03-29 13:59 - 00237486 _____ C:\Documents and Settings\Pierre\Plocha\A160302_VEN_005_DANE_2015_D.XLSX
2016-03-26 14:02 - 2016-03-26 14:02 - 00036864 _____ C:\Documents and Settings\Pierre\Plocha\1458856945_e3dd35254fffe456a5472dae15fd9e16.xls
2016-03-25 02:53 - 2016-03-25 02:53 - 00047166 _____ C:\Documents and Settings\Pierre\Dokumenty\Agents of SHIELD S03E13 - Parting Shot (AVS).srt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-04-21 18:27 - 2015-12-30 20:47 - 00027017 _____ C:\Documents and Settings\Pierre\Plocha\FRST.txt
2016-04-21 18:27 - 2015-12-30 20:47 - 00000000 ____D C:\FRST
2016-04-21 18:27 - 2015-07-13 00:36 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\temp
2016-04-21 18:26 - 2015-12-30 20:46 - 00029696 _____ C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MSGBOX.EXE
2016-04-21 18:26 - 2015-02-25 22:15 - 00000000 ___RD C:\Documents and Settings\All Users\Nabídka Start\Programy
2016-04-21 18:26 - 2015-02-25 22:15 - 00000000 ____D C:\Documents and Settings\All Users\Plocha
2016-04-21 18:26 - 2015-02-25 21:47 - 00000000 ___HD C:\Documents and Settings\Pierre\Local Settings\Data aplikací
2016-04-21 18:26 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre\Plocha
2016-04-21 18:25 - 2015-09-17 20:10 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-04-21 18:24 - 2015-09-04 12:12 - 00001819 _____ C:\Documents and Settings\Default User\Nabídka Start\Programy\Google Chrome.lnk
2016-04-21 18:24 - 2015-09-04 12:12 - 00001813 _____ C:\Documents and Settings\Default User\Plocha\Google Chrome.lnk
2016-04-21 18:22 - 2015-02-25 22:13 - 00000000 ____D C:\Pierre
2016-04-21 18:21 - 2015-02-26 00:41 - 00009328 _____ C:\WINDOWS\system32\nvAppTimestamps
2016-04-21 18:21 - 2015-02-25 22:15 - 00000000 __RHD C:\Documents and Settings\All Users\Data aplikací
2016-04-21 18:20 - 2015-04-03 10:13 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Mozilla
2016-04-21 18:18 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací
2016-04-21 18:03 - 2015-06-19 00:32 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-04-21 17:51 - 2015-02-25 21:47 - 00001599 _____ C:\Documents and Settings\Pierre\Nabídka Start\Programy\Vzdálená pomoc.lnk
2016-04-21 17:50 - 2015-03-01 10:42 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Seznam.cz
2016-04-21 17:50 - 2015-02-25 21:36 - 00001599 _____ C:\Documents and Settings\Default User\Nabídka Start\Programy\Vzdálená pomoc.lnk
2016-04-21 17:50 - 2015-02-25 21:36 - 00001507 _____ C:\Documents and Settings\All Users\Nabídka Start\Windows Update.lnk
2016-04-21 17:49 - 2015-02-25 22:16 - 01184620 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-04-21 17:49 - 2004-08-18 14:00 - 00489962 _____ C:\WINDOWS\system32\perfh005.dat
2016-04-21 17:49 - 2004-08-18 14:00 - 00098506 _____ C:\WINDOWS\system32\perfc005.dat
2016-04-21 17:46 - 2015-02-26 00:32 - 01606500 _____ C:\WINDOWS\system32\nvdrsdb0.bin
2016-04-21 17:46 - 2015-02-26 00:32 - 00000001 _____ C:\WINDOWS\system32\nvdrssel.bin
2016-04-21 17:45 - 2015-09-17 20:09 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-04-21 17:45 - 2015-09-04 12:06 - 00001054 _____ C:\WINDOWS\Tasks\ExObslI9P8NNjD3RrGI0HIktb.job
2016-04-21 17:45 - 2015-02-25 22:09 - 00000000 ____D C:\WINDOWS
2016-04-21 17:45 - 2004-08-18 14:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2016-04-21 17:44 - 2015-09-04 12:10 - 00000000 ____D C:\WINDOWS\Minidump
2016-04-21 17:44 - 2015-02-25 21:40 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-04-21 17:39 - 2015-02-25 22:09 - 00000000 ___HD C:\WINDOWS\inf
2016-04-21 17:38 - 2015-02-25 21:47 - 00000000 ____D C:\Documents and Settings\Pierre
2016-04-21 17:34 - 2015-02-26 00:32 - 01606500 _____ C:\WINDOWS\system32\nvdrsdb1.bin
2016-04-21 17:31 - 2015-03-01 11:51 - 00211826 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-System.dat
2016-04-21 17:31 - 2015-02-25 21:47 - 00000178 ___SH C:\Documents and Settings\Pierre\ntuser.ini
2016-04-21 17:31 - 2015-02-25 21:40 - 00032460 _____ C:\WINDOWS\SchedLgU.Txt
2016-04-21 17:30 - 2015-07-12 23:12 - 00000000 ____D C:\AdwCleaner
2016-04-21 17:30 - 2015-02-25 21:47 - 00000000 ___RD C:\Documents and Settings\Pierre\Nabídka Start\Programy
2016-04-21 17:30 - 2015-02-25 21:47 - 00000000 ___RD C:\Documents and Settings\Pierre\Dokumenty
2016-04-21 17:23 - 2015-09-15 23:28 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\JDownloader v2.0
2016-04-21 10:19 - 2016-02-10 18:24 - 00000000 ____D C:\Documents and Settings\All Users\Data aplikací\Tunngle
2016-04-20 01:05 - 2016-02-10 17:27 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\Tunngle
2016-04-18 21:06 - 2015-02-25 22:15 - 00000000 ___HD C:\Documents and Settings\Default User\Local Settings\Data aplikací
2016-04-14 11:15 - 2015-02-26 14:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-04-14 11:10 - 2015-02-26 14:25 - 132539272 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-04-13 15:34 - 2015-02-28 22:27 - 00000000 ____D C:\Documents and Settings\Pierre\Data aplikací\vlc
2016-04-13 02:06 - 2015-02-25 23:56 - 00001324 _____ C:\WINDOWS\system32\d3d9caps.dat
2016-04-08 11:03 - 2015-06-19 00:32 - 00797376 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-04-08 11:03 - 2015-06-19 00:32 - 00142528 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-04-07 20:48 - 2015-02-26 00:54 - 00000000 ____D C:\Program Files\Counter Strike 1.6
2016-04-07 20:48 - 2015-02-26 00:51 - 00000000 ____D C:\Documents and Settings\Pierre\GSplay
2016-04-06 00:05 - 2015-10-04 08:35 - 00001221 _____ C:\Documents and Settings\Pierre\Plocha\MiPCSuite.lnk
2016-04-06 00:05 - 2015-10-04 08:35 - 00000000 ____D C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MiPhoneManager
2016-03-29 23:16 - 2016-02-10 17:27 - 00000000 ____D C:\Program Files\Tunngle
2016-03-29 19:48 - 2015-03-01 11:51 - 01772232 _____ C:\Documents and Settings\LocalService\Local Settings\Data aplikací\WPFFontCache_v0400-S-1-5-21-1454471165-1326574676-839522115-1003-0.dat
==================== Files in the root of some directories =======
2016-04-21 18:18 - 2016-04-21 18:18 - 6494208 _____ () C:\Documents and Settings\Pierre\Data aplikací\agent.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0054272 _____ () C:\Documents and Settings\Pierre\Data aplikací\ApplicationHosting.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0065568 _____ () C:\Documents and Settings\Pierre\Data aplikací\Config.xml
2015-08-17 15:56 - 2015-08-17 15:56 - 0000245 _____ () C:\Documents and Settings\Pierre\Data aplikací\del.bat
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Documents and Settings\Pierre\Data aplikací\ExObslI9P8NNjD3RrGI0HIktb
2015-04-20 16:05 - 2015-04-20 16:05 - 1579520 _____ () C:\Documents and Settings\Pierre\Data aplikací\ExObslI9P8NNjD3RrGI0HIktb.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 0079662 _____ () C:\Documents and Settings\Pierre\Data aplikací\inst.lat
2016-04-21 18:18 - 2016-04-21 18:18 - 0015840 _____ () C:\Documents and Settings\Pierre\Data aplikací\InstallationConfiguration.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 0127488 _____ () C:\Documents and Settings\Pierre\Data aplikací\Installer.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0126464 _____ () C:\Documents and Settings\Pierre\Data aplikací\lobby.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0018432 _____ () C:\Documents and Settings\Pierre\Data aplikací\Main.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 0005568 _____ () C:\Documents and Settings\Pierre\Data aplikací\md.xml
2016-04-21 18:18 - 2016-04-21 18:18 - 0126464 _____ () C:\Documents and Settings\Pierre\Data aplikací\noah.dat
2016-04-21 18:18 - 2016-04-21 18:18 - 1027584 _____ () C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 1626777 _____ () C:\Documents and Settings\Pierre\Data aplikací\Quotesolowarm.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 1027584 _____ () C:\Documents and Settings\Pierre\Data aplikací\Sanzap.exe
2016-04-21 18:18 - 2016-04-21 18:18 - 0072717 _____ () C:\Documents and Settings\Pierre\Data aplikací\Sanzap.tst
2016-04-21 18:18 - 2016-04-21 18:18 - 0848437 _____ () C:\Documents and Settings\Pierre\Data aplikací\Silverlight.bin
2016-04-21 18:18 - 2016-04-21 18:18 - 0032038 _____ () C:\Documents and Settings\Pierre\Data aplikací\uninstall_temp.ico
2015-06-25 19:59 - 2015-10-04 08:22 - 0009216 _____ () C:\Documents and Settings\Pierre\Local Settings\Data aplikací\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-30 20:46 - 2016-04-21 18:26 - 0029696 _____ () C:\Documents and Settings\Pierre\Local Settings\Data aplikací\MSGBOX.EXE
2016-04-21 18:21 - 2016-04-21 18:21 - 0356864 _____ () C:\Documents and Settings\All Users\Data aplikací\smp2.exe
2015-09-04 11:48 - 2015-09-04 11:48 - 0004105 _____ () C:\Documents and Settings\All Users\Data aplikací\wmzddnmb.cix
Files to move or delete:
====================
C:\Documents and Settings\Pierre\Local Settings\temp\22.exe
Some files in TEMP:
====================
C:\Documents and Settings\Pierre\Local Settings\temp\130868260149721582.exe
C:\Documents and Settings\Pierre\Local Settings\temp\13086826016440908203.exe
C:\Documents and Settings\Pierre\Local Settings\temp\22.exe
C:\Documents and Settings\Pierre\Local Settings\temp\3098.exe
C:\Documents and Settings\Pierre\Local Settings\temp\8115.exe
C:\Documents and Settings\Pierre\Local Settings\temp\8333.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Browser_V5.6.11466.7_r_4714_(Build1603281525).exe
C:\Documents and Settings\Pierre\Local Settings\temp\geeplayersetup_unfix.exe
C:\Documents and Settings\Pierre\Local Settings\temp\IQIYIsetup_l_huayukeji@kb006.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u51-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u65-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\jre-8u91-windows-au.exe
C:\Documents and Settings\Pierre\Local Settings\temp\libeay32.dll
C:\Documents and Settings\Pierre\Local Settings\temp\listicka-partner-16194-1.1.8-offline.exe
C:\Documents and Settings\Pierre\Local Settings\temp\msvcr120.dll
C:\Documents and Settings\Pierre\Local Settings\temp\pps104.exe
C:\Documents and Settings\Pierre\Local Settings\temp\proxy_vole6407598957250881067.dll
C:\Documents and Settings\Pierre\Local Settings\temp\qqpcmgr_v10.5.15816.217_70557_Silence.exe
C:\Documents and Settings\Pierre\Local Settings\temp\qqpcmgr_v11.3.17195.214_78450_Silence.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Quarantine.exe
C:\Documents and Settings\Pierre\Local Settings\temp\set.exe
C:\Documents and Settings\Pierre\Local Settings\temp\setup.exe
C:\Documents and Settings\Pierre\Local Settings\temp\setup3.exe
C:\Documents and Settings\Pierre\Local Settings\temp\Setup__2140_il357769.exe
C:\Documents and Settings\Pierre\Local Settings\temp\sqlite-3.8.2-x86-sqlitejdbc.dll
C:\Documents and Settings\Pierre\Local Settings\temp\sqlite3.dll
C:\Documents and Settings\Pierre\Local Settings\temp\{94DF23C8-D11B-4097-914C-20448C9B66C9}.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End of FRST.txt ============================