Stránka 1 z 1

Prosím o kontrolu logu

Napsal: 18 zář 2016 10:59
od sebasmelichar
Dobrý den, prosím o kontrolu RSIT logu, na některých stránkách mi to píše ''502 Bad gateway nginx /1.9.2''. Celkově je počítač nabržděný . Předem děkuji za pomoc.
___

Logfile of random's system information tool 1.10 (written by random/random)
Run by Admin at 2016-09-18 11:21:08
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 28 GB (23%) free of 122 GB
Total RAM: 8145 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:21:13, on 18.9.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18450)
Boot mode: Normal

Running processes:
C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Clownfish\Clownfish.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
D:\_Instal\volumouse\volumouse32.exe
C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\monhost.exe
C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
D:\_Instal\AtomTime Pro\AtomTime.EXE
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Roaming\uTorrent\updates\3.4.8_42576\utorrentie.exe
C:\Users\Admin\AppData\Local\Host Service\httpfilter.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\Admin\AppData\Roaming\ssn\SSN.exe
D:\_Dokumenty\Plocha\RSIT.exe
C:\Program Files (x86)\trend micro\Admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hao123.com/?tn=93018773_hao_pg
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGIjVkxlyIP4NYe17aVLWqICWRlg5p-Tqs2FeOWMmBAYa3Fsl19kLB-N9-rkBMtPHlCl9ISb9VqIq7ZJHHTAqJX7Dft1p2vbYdlFyf87eg0pofPjPgackSIReFKfpeG6i-WlS4XorR66BeALPwpXhlcmcfAspBA48ynOKqADHWO01yYDtM47v10xr2TDi&q={searchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\SysWOW64\userinit.exe,
O2 - BHO: QPMIEHelper - {50F4150A-48B2-417A-BE4C-C83F580FB904} - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll
O2 - BHO: Pomocná služba pro přihlášení k účtu Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Youtube AdBlock - {95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B} - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [AtomTime] "D:\_Instal\AtomTime Pro\AtomTime.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
O4 - HKLM\..\Run: [app] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [$Volumouse$] "D:\_Instal\volumouse\volumouse.exe" /nodlg
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [RGSC] C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Voobly] "C:\Program Files (x86)\Voobly\voobly.exe" --startup
O4 - HKCU\..\Run: [Clownfish] "C:\Program Files (x86)\Clownfish\Clownfish.exe"
O4 - HKCU\..\Run: [cz.seznam.software.autoupdate] "C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe" -c
O4 - HKCU\..\Run: [cz.seznam.software.szndesktop] "C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [svchost0] "C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe"\UUC0789.exe
O4 - HKCU\..\Run: [apphide] C:\Program Files (x86)\sbqh\uc.exe
O4 - HKCU\..\Run: [produpd] C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe
O4 - HKCU\..\Run: [ssn] C:\Users\Admin\AppData\Roaming\ssn\saveup.exe
O4 - HKCU\..\Run: [Host Service] wscript "C:\Users\Admin\AppData\Local\Host Service\launchall.js"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: MEGAsync.lnk = Admin\AppData\Local\MEGAsync\MEGAsync.exe
O4 - Startup: produpd.lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: BaiduPinyin Updater (BaiduPinyinUpdater) - Unknown owner - C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe (file missing)
O23 - Service: BlueStacks Android Service (BstHdAndroidSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-Service.exe (file missing)
O23 - Service: BlueStacks Log Rotator Service (BstHdLogRotatorSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (file missing)
O23 - Service: BlueStacks Updater Service (BstHdUpdaterSvc) - Unknown owner - C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe (file missing)
O23 - Service: CloudPrinter - Unknown owner - C:\ProgramData\\CloudPrinter\\CloudPrinter.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (CmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LMIGuardianSvc - LogMeIn, Inc. - C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: QQRepair2651 - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairc1b - Unknown owner - C:\Program.exe (file missing)
O23 - Service: QQRepairFixSVC - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: winsaber - Unknown owner - C:\Program Files (x86)\WinSaber\WinSaber.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14694 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\tasks\Update Service for Youtube AdBlock.job - C:\Program Files (x86)\Youtube AdBlock\p9B5Mzp.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default

prefs.js - "browser.startup.homepage" - "http://pandasecurity.mystart.com/?pr=vm ... 575BFBDE7D"

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 23.0.0.173 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_173.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@baidu.com/npxbdcntb]
"Description"=Baiducnff Plugin
"Path"=C:\Program Files (x86)\Baidu\BaiduPinyin\3.3.2.1028\npxbdcntb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=D:\_Instal\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.66.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50709.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3528.0331]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\vmeqztvn.default\extensions\
{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}
{ea614400-e918-4741-9a97-7a972ff7c30b}

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}]
Ó¦Óñ¦Ň»Ľü°˛×°˛ĺĽţ - C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll [2014-05-30 140344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2016-01-01 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení k účtu Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}]
Youtube AdBlock - C:\Program Files (x86)\Youtube AdBlock\IEEF\zC8s4PSbnr.dll [2016-09-12 291792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}]
Bing Bar Helper - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2016-01-01 172640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8dcb7100-df86-4384-8842-8fa844297b3f} - Bing Bar - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13 1307928]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2015-06-15 296216]
"AtomTime"=D:\_Instal\AtomTime Pro\AtomTime.EXE [2015-10-19 396316]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-01 596528]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
"seznam-listicka-distribuce"=C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [2016-08-18 1062472]
"app"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"LogMeIn Hamachi Ui"=C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2016-09-14 5565960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"$Volumouse$"=D:\_Instal\volumouse\volumouse.exe [2015-08-09 94816]
"uTorrent"=C:\Users\Admin\AppData\Roaming\uTorrent\uTorrent.exe [2016-09-08 2139840]
"RGSC"=C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe [2008-11-14 305064]
"Voobly"=C:\Program Files (x86)\Voobly\voobly.exe [2016-06-19 159744]
"Clownfish"=C:\Program Files (x86)\Clownfish\Clownfish.exe [2016-08-18 1329408]
"cz.seznam.software.autoupdate"=C:\Users\Admin\AppData\Roaming\Seznam.cz\szninstall.exe [2016-08-18 1062472]
"cz.seznam.software.szndesktop"=C:\Users\Admin\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [2016-08-18 103080]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-08-28 2857248]
"svchost0"=C:\Program Files (x86)\UCBrowser\Application\UCBrowser.exe\UUC0789.exe []
"apphide"=C:\Program Files (x86)\sbqh\uc.exe [2016-09-08 221246]
"produpd"=C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe [2016-09-08 521216]
"ssn"=C:\Users\Admin\AppData\Roaming\ssn\saveup.exe [2016-09-08 29184]
"Host Service"=wscript C:\Users\Admin\AppData\Local\Host Service\launchall.js []
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-09-17 8912088]

C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
MEGAsync.lnk - C:\Users\Admin\AppData\Local\MEGAsync\MEGAsync.exe
produpd.lnk - C:\Users\Admin\AppData\Roaming\VDI\Shared\Product Updater\produpd.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux7"=wdmaud.drv
"wave8"=wdmaud.drv
"midi8"=wdmaud.drv
"mixer8"=wdmaud.drv
"aux8"=wdmaud.drv
"wave9"=wdmaud.drv
"midi9"=wdmaud.drv
"mixer9"=wdmaud.drv
"aux9"=wdmaud.drv
"VIDC.FPS1"=frapsvid.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-09-18 11:21:08 ----D---- C:\rsit
2016-09-18 11:21:08 ----D---- C:\Program Files (x86)\trend micro
2016-09-17 19:04:12 ----D---- C:\%LOCALAPPDATA%
2016-09-17 16:11:08 ----D---- C:\Program Files (x86)\Google
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\vbscript.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\urlmon.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\occache.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\inseng.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iernonce.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2016-09-15 15:45:17 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\mshtml.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iesetup.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\iertutil.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2016-09-15 15:45:16 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\jscript.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieui.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\ieframe.dll
2016-09-15 15:45:15 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\wininet.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\webcheck.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\msrating.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\jscript9.dll
2016-09-15 15:45:14 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuwebv.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wudriver.dll
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapp.exe
2016-09-15 15:36:30 ----A---- C:\Windows\SysWOW64\wuapi.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-09-15 15:36:29 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wups.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wow32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\wintrust.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\srclient.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\schannel.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\setup16.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\olepro32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\ntdll.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msiexec.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\msi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\kernel32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\instnm.exe
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptsvc.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\cryptnet.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\crypt32.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\certcli.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\asycfilt.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\appidapi.dll
2016-09-15 15:36:29 ----A---- C:\Windows\SysWOW64\advapi32.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-09-15 15:36:28 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\wdigest.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\user.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\sspicli.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\secur32.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpchttp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\rpcrt4.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msobjs.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msimsg.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msihnd.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\msaudite.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\kerberos.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\cryptbase.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\credssp.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\authui.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\auditpol.exe
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\apisetschema.dll
2016-09-15 15:36:28 ----A---- C:\Windows\SysWOW64\adtschema.dll
2016-09-15 15:29:48 ----A---- C:\Windows\SysWOW64\user32.dll
2016-09-15 15:29:47 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2016-09-15 15:29:46 ----A---- C:\Windows\SysWOW64\INETRES.dll
2016-09-15 15:29:38 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2016-09-14 17:26:29 ----D---- C:\Program Files (x86)\{5B3162EB-D13D-41BA-9F10-0091DA316387}
2016-09-14 17:26:27 ----D---- C:\Program Files (x86)\e1ry2bpi
2016-09-14 13:27:56 ----D---- C:\Program Files (x86)\LogMeIn Hamachi
2016-09-13 14:37:41 ----D---- C:\Program Files (x86)\WinSaber
2016-09-13 14:36:36 ----D---- C:\Program Files (x86)\{9EC321B2-3D20-4C7A-95B8-047A55B2827F}
2016-09-13 14:36:34 ----D---- C:\Program Files (x86)\eqt7zw22
2016-09-12 11:43:06 ----D---- C:\Program Files (x86)\Youtube AdBlock
2016-09-12 11:42:24 ----D---- C:\Users\Admin\AppData\Roaming\GameLauncher
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v4
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v3
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v2
2016-09-09 15:00:32 ----HD---- C:\Program Files (x86)\Vlc Player v1
2016-09-09 15:00:32 ----D---- C:\ProgramData\AVAST Software
2016-09-08 13:36:39 ----A---- C:\Windows\SysWOW64\kz.exe
2016-09-08 07:05:27 ----D---- C:\Users\Admin\AppData\Roaming\ssn
2016-09-08 07:05:16 ----D---- C:\Users\Admin\AppData\Roaming\VDI
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\Softlink
2016-09-08 07:03:01 ----D---- C:\Users\Admin\AppData\Roaming\KuaiZip
2016-09-08 07:02:33 ----D---- C:\Program Files (x86)\UCBrowser
2016-09-08 07:00:37 ----D---- C:\Program Files (x86)\sbqh
2016-09-08 07:00:28 ----HD---- C:\Program Files (x86)\a2d5DB9
2016-09-08 07:00:21 ----D---- C:\Users\Admin\AppData\Roaming\Profiles
2016-09-08 07:00:20 ----D---- C:\Program Files (x86)\Rerwadomeboch
2016-09-08 07:00:09 ----D---- C:\Program Files (x86)\ContentPush
2016-09-08 07:00:05 ----D---- C:\Program Files (x86)\WeatherChickn
2016-09-02 15:50:57 ----D---- C:\Users\Admin\AppData\Roaming\Windows Live Writer
2016-08-28 19:21:12 ----D---- C:\Program Files (x86)\Steam

======List of files/folders modified in the last 1 month======

2016-09-18 11:21:12 ----D---- C:\Windows\Temp
2016-09-18 11:21:12 ----D---- C:\Users\Admin\AppData\Roaming\uTorrent
2016-09-18 11:21:08 ----RD---- C:\Program Files (x86)
2016-09-18 10:03:46 ----D---- C:\Windows\inf
2016-09-18 09:33:33 ----SHD---- C:\Windows\Installer
2016-09-18 09:33:29 ----D---- C:\Windows\SysWOW64
2016-09-18 09:27:03 ----D---- C:\Windows\System32
2016-09-18 09:26:11 ----D---- C:\Users\Admin\AppData\Roaming\Seznam.cz
2016-09-18 09:21:08 ----D---- C:\Windows
2016-09-17 21:21:00 ----D---- C:\ProgramData\BlueStacksSetup
2016-09-17 21:20:56 ----D---- C:\Windows\Minidump
2016-09-17 21:20:56 ----D---- C:\Windows\Logs
2016-09-17 21:19:45 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-09-17 21:19:36 ----RD---- C:\Program Files
2016-09-17 20:05:51 ----D---- C:\Users\Admin\AppData\Roaming\.minecraft
2016-09-17 16:11:11 ----D---- C:\Windows\Tasks
2016-09-17 15:38:52 ----D---- C:\Users\Admin\AppData\Roaming\Skype
2016-09-16 16:00:15 ----D---- C:\Windows\rescache
2016-09-16 13:59:08 ----D---- C:\Windows\winsxs
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\en-US
2016-09-16 13:56:59 ----D---- C:\Windows\SysWOW64\cs-CZ
2016-09-16 13:56:58 ----D---- C:\Windows\AppPatch
2016-09-16 13:56:58 ----D---- C:\Program Files (x86)\Internet Explorer
2016-09-15 20:10:07 ----D---- C:\ProgramData\Microsoft Help
2016-09-15 20:08:29 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-09-15 20:08:08 ----SHD---- C:\System Volume Information
2016-09-15 16:37:47 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-09-15 16:37:43 ----D---- C:\Windows\SysWOW64\Macromed
2016-09-12 11:43:00 ----HD---- C:\ProgramData
2016-09-08 13:35:14 ----D---- C:\Program Files (x86)\Common Files\Steam
2016-09-08 07:07:12 ----D---- C:\ProgramData\panda_url_filtering
2016-09-08 07:00:04 ----SD---- C:\Users\Admin\AppData\Roaming\Microsoft
2016-09-01 11:33:02 ----D---- C:\Program Files (x86)\Cheat Engine 6.4
2016-08-23 20:16:03 ----D---- C:\Program Files (x86)\Voobly

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys []
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 cmderd;COMODO Internet Security Eradication Driver; C:\Windows\System32\DRIVERS\cmderd.sys []
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\Windows\system32\DRIVERS\cmdguard.sys []
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\Windows\System32\DRIVERS\cmdhlp.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys []
R1 inspect;COMODO Internet Security Firewall Driver; C:\Windows\system32\DRIVERS\inspect.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R2 ntk_PowerDVD;ntk_PowerDVD; \??\C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys [2011-12-08 75248]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys []
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys []
R3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys []
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys []
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys []
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys []
R3 ScreamBAudioSvc;ScreamBee Audio; C:\Windows\system32\drivers\ScreamingBAudio64.sys []
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys []
S1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\QMUdisk64.sys []
S1 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\softaal64.sys []
S1 SRepairDrv;SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\SRepairDrv []
S2 BstHdDrv;BlueStacks Hypervisor; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys []
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.5.17490.219\TsNetHlpX64.sys []
S3 dmvsc;dmvsc; C:\Windows\system32\drivers\dmvsc.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2016-05-21 26192]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys []
S3 Revoflt;Revoflt; C:\Windows\system32\DRIVERS\revoflt.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TSSKX64;TSSKX64; C:\Windows\System32\drivers\tsskx64.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys []
S3 vmbus;vmbus; C:\Windows\system32\drivers\vmbus.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2015-11-21 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 CkerloyClient;CkerloyClient; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 CmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2016-06-13 5817200]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [2016-09-14 2621448]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2015-06-23 18856]
R2 LMIGuardianSvc;LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [2016-09-14 419248]
R2 winsaber;winsaber; C:\Program Files (x86)\WinSaber\WinSaber.exe [2016-09-13 521496]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
R3 BBUpdate;BBUpdate; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe [2016-06-17 240408]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-08-28 1465120]
S2 BBSvc;BingBar Service; C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe [2016-06-17 193816]
S2 BstHdAndroidSvc;BlueStacks Android Service; C:\Program Files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android []
S2 BstHdLogRotatorSvc;BlueStacks Log Rotator Service; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe []
S2 BstHdUpdaterSvc;BlueStacks Updater Service; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe []
S2 CloudPrinter;CloudPrinter; C:\ProgramData\\CloudPrinter\\CloudPrinter.exe shuz -f C:\ProgramData\\CloudPrinter\\CloudPrinter.dat -l -a []
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-05-17 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-05-17 125112]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S2 QQRepair2651;QQRepair2651; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepair2651 []
S2 QQRepairc1b;QQRepairc1b; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairc1b []
S2 QQRepairFixSVC;QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\QQRepairFixSVC []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-15 270528]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 BaiduPinyinUpdater;BaiduPinyin Updater; C:\Program Files (x86)\Baidu\BaiduPinyinUpdate\bdupdate.exe []
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2016-06-13 2271928]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-09-17 153752]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2015-06-03 217888]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2016-06-10 1289968]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-05-17 51376]
S4 CLHNServiceForPowerDVD;CLHNServiceForPowerDVD; C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe [2011-12-08 83240]
S4 CyberLink PowerDVD 11.0 Monitor Service;CyberLink PowerDVD 11.0 Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe [2011-12-07 75048]
S4 CyberLink PowerDVD 11.0 Service;CyberLink PowerDVD 11.0 Service; C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServerForPDVD11.exe [2011-12-07 292136]
S4 EasyTuneEngineService;EasyTune Engine; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\EasyTuneEngineService.exe [2015-08-05 138240]
S4 gadjservice;GIGABYTE Adjust; C:\Program Files (x86)\GIGABYTE\AppCenter\AdjustService.exe [2015-06-25 17920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-05-17 135848]
S4 OcButtonService;OcButtonService; C:\Program Files (x86)\GIGABYTE\EasyTuneEngineService\OcButtonService.exe [2015-08-05 117760]

-----------------EOF-----------------

Re: Prosím o kontrolu logu

Napsal: 18 zář 2016 11:47
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Prosím o kontrolu logu

Napsal: 18 zář 2016 13:23
od sebasmelichar
# AdwCleaner v6.020 - Log soubor vytvořen 18/09/2016 na 14:06:01
# Aktualizováno dne 14/09/2016 z ToolsLib
# Databáze : 2016-09-17.1 [Server]
# Operační systém : Windows 7 Professional Service Pack 1 (X64)
# Uživatelské jméno : Admin - CORE-I3
# Beží od : D:\_Dokumenty\Plocha\adwcleaner_6.020.exe
# Mod: Čištění
# Podpora : https://toolslib.net/forum



***** [ Služby ] *****

[-] Služby smazány:QQRepair2651
[-] Služby smazány:QQRepairc1b
[-] Služby smazány:QQRepairFixSVC
[-] Služby smazány:QMUdisk
[-] Služby smazány:TSSKX64
[-] Služby smazány:softaal
[-] Služby smazány:CloudPrinter
[-] Služby smazány:SRepairDrv
[-] Služby smazány:tsnethlpx64
[-] Služby smazány:winsaber


***** [ Adresáře ] *****

[-] Adresář smazán:C:\Users\Admin\AppData\LocalLow\Youtube AdBlock
[-] Adresář smazán:C:\Program Files (x86)\Youtube AdBlock
[#] Adresář nelze smazat:C:\Users\Admin\AppData\LocalLow\Youtube AdBlock
[#] Adresář nelze smazat:C:\Program Files (x86)\Youtube AdBlock
[-] Adresář smazán:C:\Users\Admin\AppData\Local\Host Service
[#] Adresář nelze smazat:C:\Users\Admin\AppData\LocalLow\Youtube AdBlock
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\cpuminer
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\SSN
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\tencent
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\gplyra
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\Kuaizip
[#] Adresář nelze smazat:C:\Users\Admin\AppData\Roaming\KuaiZip
[#] Adresář nelze smazat:C:\Users\Admin\AppData\Roaming\Tencent
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\Softlink
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\VDI
[-] Adresář smazán:C:\Users\Admin\AppData\Roaming\GameLauncher\Seviler
[-] Adresář smazán:C:\Users\Admin\AppData\Local\VirtualStore\Program Files (x86)\tencent
[#] Adresář nelze smazat:C:\Users\Admin\AppData\Local\VirtualStore\Program Files (x86)\Tencent
[-] Adresář smazán:C:\ProgramData\tencent
[-] Adresář smazán:C:\ProgramData\TXQMPC
[-] Adresář smazán:C:\ProgramData\CloudPrinter
[-] Adresář smazán:C:\ProgramData\Ronzap
[-] Adresář smazán:C:\ProgramData\Ronzaps
[#] Adresář nelze smazat:C:\ProgramData\Tencent
[#] Adresář nelze smazat:C:\ProgramData\Application Data\tencent
[#] Adresář nelze smazat:C:\ProgramData\Application Data\TXQMPC
[#] Adresář nelze smazat:C:\ProgramData\Application Data\CloudPrinter
[#] Adresář nelze smazat:C:\ProgramData\Application Data\Ronzap
[#] Adresář nelze smazat:C:\ProgramData\Application Data\Ronzaps
[#] Adresář nelze smazat:C:\ProgramData\Application Data\Tencent
[-] Adresář smazán:C:\Program Files (x86)\OLBPre
[-] Adresář smazán:C:\Program Files (x86)\WeatherChickn
[-] Adresář smazán:C:\Program Files (x86)\ContentPush
[-] Adresář smazán:C:\Program Files (x86)\WinSaber
[#] Adresář nelze smazat:C:\Program Files (x86)\winsaber
[#] Adresář nelze smazat:C:\Program Files (x86)\Youtube AdBlock
[-] Adresář smazán:C:\Program Files (x86)\Common Files\tencent
[#] Adresář nelze smazat:C:\Program Files (x86)\Common Files\Tencent
[-] Adresář smazán:C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\tencent
[#] Adresář nelze smazat:C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Tencent
[#] Adresář nelze smazat:C:\Users\Admin\AppData\Roaming\ssn


***** [ Soubory ] *****

[-] Soubor smazán:C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\produpd.lnk
[-] Soubor smazán:C:\Windows\SysNative\drivers\TSSKX64.sys
[-] Soubor smazán:C:\Windows\SysNative\drivers\TFsFltX64.sys
[-] Soubor smazán:C:\Windows\SysNative\drivers\KuaiZipDrive2.sys
[-] Soubor smazán:C:\Program Files (x86)\Mozilla Firefox\wtsapi32.dll
[-] Soubor smazán:C:\Windows\SysWOW64\findit.xml
[-] Soubor smazán:C:\Windows\SysWOW64\drivers\TS888x64.sys
[#] Soubor smazán:C:\Program Files (x86)\Mozilla Firefox\wtsapi32.dll
[#] Soubor smazán:C:\Program Files (x86)\Mozilla Firefox\wtsapi32.dll
[#] Soubor smazán:C:\Program Files (x86)\Mozilla Firefox\wtsapi32.dll
[#] Soubor smazán:C:\Program Files (x86)\Mozilla Firefox\wtsapi32.dll


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Youtube AdBlock
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Youtube AdBlock_is1
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Youtube AdBlock
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Youtube AdBlock_is1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[#] Klíč smazán po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{D42C3A49-ABAF-464B-BBCE-991C3DD395E8}
[#] Klíč smazán po restartování:{38DD0B4A-E4E0-4A57-99EE-DCCB185B4728}
[#] Klíč smazán po restartování:{45965C76-4C88-4512-9358-368483E1C3B1}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{D8CB24E3-DDA3-4B7F-8BA3-871DB7D3D986}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{F6DF4318-A699-4E88-BE1D-84F4A009B08A}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{D8CB24E3-DDA3-4B7F-8BA3-871DB7D3D986}
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Classes\Interface\{F6DF4318-A699-4E88-BE1D-84F4A009B08A}
[-] Klíč smazán:HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Application Hosting
[#] Klíč smazán po restartování:[x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Application Hosting
[-] Klíč smazán:HKLM\SOFTWARE\Classes\BaiducnAx.ScreenShotAx
[-] Klíč smazán:HKLM\SOFTWARE\Classes\BaiducnAx.ScreenShotAx.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\BaiduImeDictFile
[-] Klíč smazán:HKLM\SOFTWARE\Classes\BaiduImeSkinFile
[-] Klíč smazán:HKLM\SOFTWARE\Classes\metnsd
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[-] Klíč smazán:HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\qmgcfiles
[-] Klíč smazán:HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid
[-] Klíč smazán:HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\BaiducnAx.ScreenShotAx
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\BaiducnAx.ScreenShotAx.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\BaiduImeDictFile
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\BaiduImeSkinFile
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\metnsd
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\OCComSDK.ComSDK
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\OCComSDK.ComSDK.1
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\qmgcfiles
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid
[#] Klíč smazán po restartování:[x64] HKLM\SOFTWARE\Classes\QQAppIEAgentEx.AgentForAndroid.1
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\{51BEE30D-EEC8-4BA3-930B-298B8E759EB1}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{70DE12EA-79F4-46BC-9812-86DB50A2FD64}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{754DF2CE-51E8-4895-B53C-6381418B84AE}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{B9D64D3B-BE75-4FA2-B94A-C4AE772A0146}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\CLSID\{D64016F6-4D8E-4B35-AB22-9B2060800112}
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Classes\CLSID\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{6B3732AA-F6D4-4F16-9E22-49EDC52C9514}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{B9E49847-9822-4139-BC55-7173ED1ADA11}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{FA7B2795-C0C8-4A58-8672-3F8D80CC0270}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\Interface\{47A1DF02-BCE4-40C3-AE47-E3EA09A65E4A}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{6E1533F0-E0B5-465A-9F16-98FF0C76D493}
[-] Klíč smazán:HKLM\SOFTWARE\Classes\TypeLib\{1112F282-7099-4624-A439-DB29D6551552}
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{29B6CFD5-0064-411A-8C42-9890C83F9921}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D64016F6-4D8E-4B35-AB22-9B2060800112}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{50F4150A-48B2-417A-BE4C-C83F580FB904}
[-] Klíč smazán:HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95E84BD3-3604-4AAC-B2CA-D9AC3E55B64B}
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[-] Hodnota smazána:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved [{754DF2CE-51E8-4895-B53C-6381418B84AE}]
[-] Klíč smazán:HKU\.DEFAULT\Software\ompndb
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\IM
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\PRODUCTSETUP
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\ssn
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\csastats
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\INSTALLPATH\STATUS
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\UCBrowserPID
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\SNDA
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\COMMONMSG
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\VDI
[-] Klíč smazán:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\ssn
[#] Klíč smazán po restartování:HKU\S-1-5-18\Software\ompndb
[#] Klíč smazán po restartování:HKCU\Software\IM
[#] Klíč smazán po restartování:HKCU\Software\PRODUCTSETUP
[#] Klíč smazán po restartování:HKCU\Software\ssn
[#] Klíč smazán po restartování:HKCU\Software\csastats
[#] Klíč smazán po restartování:HKCU\Software\INSTALLPATH\STATUS
[#] Klíč smazán po restartování:HKCU\Software\UCBrowserPID
[#] Klíč smazán po restartování:HKCU\Software\SNDA
[#] Klíč smazán po restartování:HKCU\Software\COMMONMSG
[#] Klíč smazán po restartování:HKCU\Software\VDI
[-] Klíč smazán:HKLM\SOFTWARE\Mindspark
[-] Klíč smazán:HKLM\SOFTWARE\mtRonzap
[-] Klíč smazán:HKLM\SOFTWARE\UCBrowserPID
[-] Klíč smazán:HKLM\SOFTWARE\youndooSoftware
[-] Klíč smazán:HKLM\SOFTWARE\WinSaberSvc
[-] Klíč smazán:HKLM\SOFTWARE\ompndb
[#] Klíč smazán po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ssn
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AppHelper
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WeatherChickn
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ContentPush
[#] Klíč smazán po restartování:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Youtube AdBlock
[#] Klíč smazán po restartování:[x64] HKCU\Software\IM
[#] Klíč smazán po restartování:[x64] HKCU\Software\PRODUCTSETUP
[#] Klíč smazán po restartování:[x64] HKCU\Software\ssn
[#] Klíč smazán po restartování:[x64] HKCU\Software\csastats
[#] Klíč smazán po restartování:[x64] HKCU\Software\INSTALLPATH\STATUS
[#] Klíč smazán po restartování:[x64] HKCU\Software\UCBrowserPID
[#] Klíč smazán po restartování:[x64] HKCU\Software\SNDA
[#] Klíč smazán po restartování:[x64] HKCU\Software\COMMONMSG
[#] Klíč smazán po restartování:[x64] HKCU\Software\VDI
[-] Klíč smazán:[x64] HKLM\SOFTWARE\ompndb
[#] Klíč smazán po restartování:[x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\ssn
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\cpuminer
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OLBPre
[-] Klíč smazán:[x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WarThunder
[-] Hodnota smazána:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\Microsoft\Windows\CurrentVersion\Run [apphide]
[#] Hodnota smazána po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Run [apphide]
[#] Hodnota smazána po restartování:[x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [apphide]
[-] Hodnota smazána:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\Microsoft\Windows\CurrentVersion\Run [ssn]
[#] Hodnota smazána po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssn]
[#] Hodnota smazána po restartování:[x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssn]
[-] Hodnota smazána:HKU\S-1-5-21-148509160-2209469422-3751760370-1000\Software\Microsoft\Windows\CurrentVersion\Run [produpd]
[#] Hodnota smazána po restartování:HKCU\Software\Microsoft\Windows\CurrentVersion\Run [produpd]
[#] Hodnota smazána po restartování:[x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [produpd]
[-] Klíč smazán:HKLM\SOFTWARE\Classes\AppID\DownloadProxy.EXE
[-] Klíč smazán:HKLM\SOFTWARE\Microsoft\Internet Explorer\SEARCHSCOPES\IELNKSRCH
[-] Klíč smazán:HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP
[-] Klíč smazán:HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\QQPCRTP
[-] Hodnota smazána:HKCU\Environment [SNF]
[-] Hodnota smazána:HKCU\Environment [SNP]
[-] Klíč smazán:HKLM\SOFTWARE\MozillaPlugins\@qq.com/npandroidassistant
[#] Klíč smazán po restartování:HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Application Hosting
[-] Klíč smazán:HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Ronzap.exe
[-] Hodnota smazána:HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [AndroidServer.exe]
[-] Klíč smazán:HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\RONZAP.EXE
[#] Klíč smazán po restartování:HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\IELNKSRCH
[-] Klíč smazán:HKEY_CLASSES_ROOT\.qmgc


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [15545 Bajtů] - [18/09/2016 14:06:01]
C:\AdwCleaner\AdwCleaner[S0].txt - [14615 Bajtů] - [18/09/2016 14:05:25]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [15695 Bajtů] ##########

Re: Prosím o kontrolu logu

Napsal: 18 zář 2016 13:40
od sebasmelichar
Moc děkuji za pomoc po projetí AdwCleanerem je po problémech.

Re: Prosím o kontrolu logu

Napsal: 18 zář 2016 16:49
od Rudy
Mělo by se to ještě dočistit. Dejte nový log RSIT.