Čištění pc
Napsal: 23 zář 2016 15:03
Dobrý den rozhodl sem se vyčistit počítač přítelkyně který je již 5 let starý a je kompletně zpomalený a zasekaný,například načítání windowsu trvá okolo 30 min a následně spouštění aplikací 15 min... Děkuji za pomoc.
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2016
Ran by nela (administrator) on CHAN (23-09-2016 14:50:01)
Running from C:\Users\nela\Desktop
Loaded Profiles: nela (Available Profiles: nela & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: "C:\Program Files\Birdkiss\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Qksee Pvt Ltd.) C:\Program Files\qksee\qkseeSvc.exe
() C:\Program Files\InterHop\InterHop.exe
() C:\Windows\System32\PnkBstrA.exe
(Crawler Group, LLC) C:\Program Files\Spyware Terminator\st_rsser.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
() C:\ProgramData\Birdkiss\Birdkiss.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Crawler Group, LLC) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMSWCS.EXE
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(forum.viry.cz) C:\Users\nela\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1417216 2009-06-05] (VIA)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\Update\realsched.exe [296056 2012-04-27] (RealNetworks, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1246544 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM\...\Run: [PrivitizeVPN] => C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe [196784 2012-09-10] (OOO Industry)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Family Tree Builder Update] => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2526208 2013-05-23] (MyHeritage)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [8900328 2016-08-08] (AVAST Software)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [5318992 2015-12-15] (Crawler Group, LLC)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [5557584 2015-12-15] (Crawler Group, LLC)
HKLM\...\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (CANON INC.)
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\MountPoints2: {4c3c45cc-db3d-11de-ba43-806e6f6e6963} - D:\Msetup4.exe
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\MountPoints2: {fbc08525-e05e-11e0-8f1d-002618e52063} - E:\Autorun.exe
AppInit_DLLs: c:\progra~1\optimi~1\optpro~1.dll => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-07-12] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2010-02-16]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\nela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk [2015-12-02]
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> (No File)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
CHR HKU\S-1-5-21-2460206527-1493759754-90791392-1000\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 01 mswsock.dll No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll No File ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 02 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 03 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 04 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 05 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 06 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 17 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 18 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{FDD04CC3-AE0F-4CDB-96BD-C490418BD7B2}: [NameServer] 62.129.50.20,85.135.32.100
Tcpip\..\Interfaces\{FDD04CC3-AE0F-4CDB-96BD-C490418BD7B2}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422038033&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.seznam.cz/
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
URLSearchHook: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 - (No Name) - {bfc39e47-d643-4dc2-aa1d-61377501c844} - No File
SearchScopes: HKLM -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422038033&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638&q={searchTerms}
SearchScopes: HKLM -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCxdm490YYCZ&ptb=lN0Hwp9EROc1zzW.5xn.sQ&psa=&ind=2010061819&ptnrS=ZCxdm490YYCZ&si=&st=sb&n=77cf1bfb&searchfor={searchTerms}
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=292&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKLM -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> search13 URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {1167AC8F-0B3C-428C-ADB6-9F0A8B7D1FF6} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {628BECE3-F266-418D-9DF4-6DFF17980A4F} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6449A477-E910-4105-BDAD-16BA915154C0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6AD9972A-8842-4CD9-A65E-D62D14B11EF5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {9600320E-C514-4206-B82F-83E846FC2443} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {A885C9E5-BC26-49A4-A01E-F202067084F5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {BEE71CD1-E2E7-4B19-B9D3-6920F5C9DBE7} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {C5334550-FA53-4631-A906-FF6D32AD4411} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {CDEB261D-C6C4-4370-9B7A-33E50BDFED74} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {DB2DF2D1-E683-40DA-96B9-A1A7396332AE} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {EAF19D11-7800-4E47-A37B-02089180ECC0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-11-04] (IObit)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-04-27] (RealPlayer)
BHO: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-04-04] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-07-12] (AVAST Software)
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-04-04] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKLM - No Name - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No File
Toolbar: HKLM - No Name - !{eec0f710-38b5-4aba-99bf-ec87564a4e13} - No File
Toolbar: HKLM - No Name - !{F9639E4A-801B-4843-AEE3-03D9DA199E77} - No File
Toolbar: HKLM - No Name - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
FireFox:
========
FF ProfilePath: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default
FF DefaultSearchEngine: omiga-plus
FF DefaultSearchUrl: hxxps://www.google.com/search
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: omiga-plus
FF Keyword.URL: hxxps://www.google.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-13] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2010-01-12] (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Users\nela\Desktop\Picasa3\npPicasa3.dll [No File]
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-04-04] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll [2012-03-29] ( Microsoft Corporation)
FF Plugin: @mywebsearch.com/Plugin -> C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll [No File]
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.3.37 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.3.37 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2460206527-1493759754-90791392-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\user.js [2015-04-10]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\askcom.xml [2013-07-05]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\askcomsearch.xml [2013-05-20]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\bingp.xml [2013-05-30]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\funmoods.xml [2014-08-12]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\icqplugin.xml [2015-04-04]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\MyStart Search.xml [2012-09-22]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\omiga-plus.xml [2015-02-12]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\Search_Results.xml [2012-03-31]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\yahoo-zugo.xml [2011-10-27]
FF Extension: (FF Toolbar) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\fftoolbar2014@etech.com [2015-01-23] [not signed]
FF Extension: (WebCake) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\plugins@getwebcake.com.xpi [2013-11-28] [not signed]
FF Extension: (Seznam lištička) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04] [not signed]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-02-16] [not signed]
FF HKLM\...\Firefox\Extensions: [m3ffxtbr@mywebsearch.com] - C:\Program Files\MyWebSearch\bar\1.bin => not found
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: (RealPlayer Browser Record Plugin) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-04-27] [not signed]
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox => not found
FF HKLM\...\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] - C:\Program Files\Web Assistant\Firefox => not found
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-07-12]
FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\extensions\fftoolbar2014@etech.com
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-07-12]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx <not found>
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-29]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-04-27]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-07-12] (AVAST Software)
S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 BirdkissP; C:\ProgramData\Birdkiss\Birdkiss.exe [418688 2016-06-07] ()
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-04-19] ()
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 InterHop; C:\Program Files\InterHop\InterHop.exe [409320 2016-09-21] ()
R2 iSafeService; C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [118048 2016-05-23] (Elex do Brasil Participações Ltda)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2904864 2015-06-02] (IObit)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S3 npggsvc; C:\Windows\system32\GameMon.des [3743800 2010-04-04] (INCA Internet Co., Ltd.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-04-19] ()
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2013-07-06] ()
R2 qkseeService; C:\Program Files\qksee\qkseeSvc.exe [690904 2016-04-27] (Qksee Pvt Ltd.)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [2114384 2015-12-15] (Crawler Group, LLC)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 adusbser; C:\Windows\System32\DRIVERS\adusbser.sys [93440 2006-10-23] (AnyDATA Corporation)
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34008 2016-07-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-07-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91680 2016-07-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-07-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [60424 2016-07-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [816304 2016-07-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [438296 2016-07-13] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [118152 2016-07-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [224616 2016-08-05] (AVAST Software)
S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed]
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 iSafeKrnl; C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys [227776 2016-05-23] (Elex do Brasil Participações Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [50280 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys [97912 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlMon; C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [45032 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys [73232 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [59152 2016-05-19] (Elex do Brasil Participações Ltda)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [114376 2013-10-23] (Power Software Ltd)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-11-14] (Duplex Secure Ltd.)
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1056256 2009-06-02] (VIA Technologies, Inc.)
U3 azzh22jc; C:\Windows\system32\Drivers\azzh22jc.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-23 14:50 - 2016-09-23 14:51 - 00036523 _____ C:\Users\nela\Desktop\FRST.txt
2016-09-23 14:49 - 2016-09-23 14:50 - 00000000 ____D C:\FRST
2016-09-23 14:48 - 2016-09-23 14:48 - 00112640 _____ (forum.viry.cz) C:\Users\nela\Desktop\FRSTLauncher.exe
2016-09-23 14:45 - 2016-09-23 14:45 - 01753088 _____ (Farbar) C:\Users\nela\Desktop\FRST.exe
2016-09-21 19:09 - 2016-09-21 19:10 - 00000000 ____D C:\Program Files\InterHop
2016-09-13 22:20 - 2016-09-13 22:20 - 20448960 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2016-09-12 19:33 - 2016-09-12 19:33 - 00852405 _____ C:\Users\nela\Downloads\Opravene_zaznamove_archy_DT_podzim_2016.zip
2016-09-12 15:13 - 2016-09-12 15:13 - 00168880 _____ C:\Users\nela\Downloads\skener_sharp@zs-klokanek.eu_20160516_095303 (1).pdf
2016-09-12 15:07 - 2016-09-12 15:07 - 00277409 _____ C:\Users\nela\Downloads\prihlaska2016.pdf
2016-09-12 12:54 - 2016-09-12 12:54 - 00054262 _____ C:\Users\nela\Downloads\Protokol_o_vysledcich_SC_MZ_podzim_2016.zip
2016-09-02 17:10 - 2016-09-02 17:10 - 00192774 _____ C:\Users\nela\Downloads\CJL_podzim_2016_DT.pdf
2016-08-29 17:50 - 2016-08-29 17:50 - 70757971 _____ C:\Users\nela\Downloads\maturita-anglictina-didakticky-test-poslech-2016-jaro.zip
2016-08-27 13:36 - 2016-08-27 13:36 - 00366094 _____ C:\Users\nela\Downloads\kriteria_prijimaciho_rizeni_3kolo_2016_2017.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-23 14:20 - 2015-12-01 18:01 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-09-23 12:42 - 2014-04-16 20:15 - 00000000 ____D C:\Program Files\Opera
2016-09-23 11:35 - 2016-06-07 19:28 - 00000000 _____ C:\Users\Public\Documents\report.dat
2016-09-23 11:35 - 2013-06-08 14:20 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2016-09-23 11:35 - 2012-04-27 11:25 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-23 11:33 - 2016-04-27 13:57 - 00000000 ____D C:\Program Files\qksee
2016-09-23 11:33 - 2012-01-01 10:41 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-23 11:33 - 2010-07-22 19:25 - 00000000 ____D C:\Program Files\TeamViewer
2016-09-23 11:33 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-21 19:18 - 2014-03-29 14:50 - 00000000 ____D C:\ProgramData\Spyware Terminator
2016-09-18 20:41 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-18 20:41 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-18 20:31 - 2015-11-04 21:11 - 00000000 ____D C:\ProgramData\ProductData
2016-09-18 20:30 - 2015-07-15 20:19 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-09-13 22:21 - 2013-03-19 17:49 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-09-13 22:21 - 2011-09-24 16:03 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-09-13 22:20 - 2009-12-31 20:08 - 00000000 ____D C:\Windows\system32\Macromed
2016-09-12 15:10 - 2016-02-10 21:13 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-08-30 13:56 - 2010-02-01 16:30 - 00000000 ____D C:\Users\nela\AppData\Roaming\Skype
2016-08-30 12:55 - 2016-06-14 15:15 - 00000000 ___RD C:\Program Files\Skype
2016-08-30 12:55 - 2010-02-01 16:28 - 00000000 ____D C:\ProgramData\Skype
==================== Files in the root of some directories =======
2012-09-22 12:11 - 2012-09-22 12:11 - 1662242 _____ () C:\Program Files\EM3patch1.zip
2011-06-03 15:49 - 2011-10-26 19:59 - 0087608 _____ () C:\Users\nela\AppData\Roaming\inst.exe
2011-06-03 15:49 - 2011-10-26 19:59 - 0007887 _____ () C:\Users\nela\AppData\Roaming\pcouffin.cat
2011-06-03 15:49 - 2011-10-26 19:59 - 0001144 _____ () C:\Users\nela\AppData\Roaming\pcouffin.inf
2011-06-03 15:50 - 2011-10-26 19:59 - 0000033 _____ () C:\Users\nela\AppData\Roaming\pcouffin.log
2011-06-03 15:49 - 2011-10-26 19:59 - 0047360 _____ (VSO Software) C:\Users\nela\AppData\Roaming\pcouffin.sys
2011-06-03 15:50 - 2011-10-10 22:56 - 0000668 _____ () C:\Users\nela\AppData\Roaming\vso_ts_preview.xml
2010-07-20 17:25 - 2010-07-26 12:49 - 0000600 _____ () C:\Users\nela\AppData\Roaming\winscp.rnd
2010-07-22 00:55 - 2016-01-31 18:03 - 0096256 _____ () C:\Users\nela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-05 15:26 - 2012-08-05 15:26 - 0027520 _____ () C:\Users\nela\AppData\Local\dt.dat
2016-01-20 01:06 - 2016-01-20 01:06 - 0004415 _____ () C:\Users\nela\AppData\Local\recently-used.xbel
2010-07-12 11:22 - 2010-07-12 11:22 - 0007609 _____ () C:\Users\nela\AppData\Local\Resmon.ResmonCfg
2012-09-21 20:20 - 2012-09-21 20:20 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-02-04 14:52 - 2011-10-26 20:13 - 0004773 _____ () C:\ProgramData\hpzinstall.log
2015-11-30 11:22 - 2016-01-08 14:36 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Users\nela\jagex_runescape_preferences.dat
C:\Users\nela\jagex_runescape_preferences2.dat
Some files in TEMP:
====================
C:\Users\nela\AppData\Local\Temp\ASCSetup_9871384.exe
C:\Users\nela\AppData\Local\Temp\lowproc.exe
C:\Users\nela\AppData\Local\Temp\MSETUP4.EXE
C:\Users\nela\AppData\Local\Temp\rnsetup0.exe
C:\Users\nela\AppData\Local\Temp\rnsetup1.exe
C:\Users\nela\AppData\Local\Temp\rnsetup2.exe
C:\Users\nela\AppData\Local\Temp\SkypeSetup.exe
C:\Users\nela\AppData\Local\Temp\stubhelper.dll
C:\Users\nela\AppData\Local\Temp\vywa8pa1.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\system32\Macromed\Flash\FlashUtil32_23_0_0_162_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{AAF13F04-653E-4678-9CE3-23660447CBC9}.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: AVG Internet Security 2012 (Disabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AS: AVG Internet Security 2012 (Disabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Internet Security 2012 (Disabled) {621CC794-9486-F902-D092-0484E8EA828B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\nela\Desktop" je 165801 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
"C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
"C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
"C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\hry\Steam\Steam.exe" -silent [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-09-2016
Ran by nela (administrator) on CHAN (23-09-2016 14:50:01)
Running from C:\Users\nela\Desktop
Loaded Profiles: nela (Available Profiles: nela & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: "C:\Program Files\Birdkiss\Application\chrome.exe" "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeSvc2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Qksee Pvt Ltd.) C:\Program Files\qksee\qkseeSvc.exe
() C:\Program Files\InterHop\InterHop.exe
() C:\Windows\System32\PnkBstrA.exe
(Crawler Group, LLC) C:\Program Files\Spyware Terminator\st_rsser.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
() C:\ProgramData\Birdkiss\Birdkiss.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(Elex do Brasil Participações Ltda) C:\Program Files\Elex-tech\YAC\iSafeTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(VIA) C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(MyHeritage) C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Crawler Group, LLC) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(IObit) C:\Program Files\IObit\IObit Uninstaller\UninstallMonitor.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMSWCS.EXE
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Google Inc.) C:\Program Files\Birdkiss\Application\chrome.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(Opera Software) C:\Program Files\Opera\39.0.2256.71\opera.exe
(forum.viry.cz) C:\Users\nela\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [HDAudDeck] => C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe [1417216 2009-06-05] (VIA)
HKLM\...\Run: [TkBellExe] => C:\Program Files\Real\RealPlayer\Update\realsched.exe [296056 2012-04-27] (RealNetworks, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [1246544 2010-11-03] (Logitech, Inc.)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM\...\Run: [PrivitizeVPN] => C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe [196784 2012-09-10] (OOO Industry)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [Family Tree Builder Update] => C:\Program Files\MyHeritage\Bin\FTBCheckUpdates.exe [2526208 2013-05-23] (MyHeritage)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [8900328 2016-08-08] (AVAST Software)
HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [5318992 2015-12-15] (Crawler Group, LLC)
HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [5557584 2015-12-15] (Crawler Group, LLC)
HKLM\...\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1284680 2014-01-17] (CANON INC.)
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\MountPoints2: {4c3c45cc-db3d-11de-ba43-806e6f6e6963} - D:\Msetup4.exe
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\MountPoints2: {fbc08525-e05e-11e0-8f1d-002618e52063} - E:\Autorun.exe
AppInit_DLLs: c:\progra~1\optimi~1\optpro~1.dll => No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2016-07-12] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2010-02-16]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\nela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk [2015-12-02]
ShortcutTarget: Sledovat výstrahy inkoustu - HP Photosmart 5510 series.lnk -> (No File)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
CHR HKU\S-1-5-21-2460206527-1493759754-90791392-1000\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 01 mswsock.dll No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll No File ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog9 01 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 02 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 03 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 04 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 05 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 06 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 17 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Winsock: Catalog9 18 C:\Windows\system32\nvLsp.dll [268832 2009-04-19] (NVIDIA)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{FDD04CC3-AE0F-4CDB-96BD-C490418BD7B2}: [NameServer] 62.129.50.20,85.135.32.100
Tcpip\..\Interfaces\{FDD04CC3-AE0F-4CDB-96BD-C490418BD7B2}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422038033&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxps://www.seznam.cz/?clid=22668
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.seznam.cz/
HKU\S-1-5-21-2460206527-1493759754-90791392-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://isearch.omiga-plus.com/?type=hppp&ts=1422038096&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638
URLSearchHook: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 - (No Name) - {bfc39e47-d643-4dc2-aa1d-61377501c844} - No File
SearchScopes: HKLM -> DefaultScope {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://search.seznam.cz/?sourceid=quicksearch_22668&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422038033&from=obw&uid=WDCXWD6400AADS-00M2B0_WD-WCAV5287463874638&q={searchTerms}
SearchScopes: HKLM -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZCxdm490YYCZ&ptb=lN0Hwp9EROc1zzW.5xn.sQ&psa=&ind=2010061819&ptnrS=ZCxdm490YYCZ&si=&st=sb&n=77cf1bfb&searchfor={searchTerms}
SearchScopes: HKLM -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://dts.search-results.com/sr?src=ieb&appid=292&systemid=406&sr=0&q={searchTerms}
SearchScopes: HKLM -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> search13 URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0388404D-6072-4CEB-B521-8F090FEAEE57} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {1167AC8F-0B3C-428C-ADB6-9F0A8B7D1FF6} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {15C4DF55-4B67-495A-A3D3-A497C4A49EE0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {56256A51-B582-467e-B8D4-7786EDA79AE0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {628BECE3-F266-418D-9DF4-6DFF17980A4F} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6449A477-E910-4105-BDAD-16BA915154C0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {6AD9972A-8842-4CD9-A65E-D62D14B11EF5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {9600320E-C514-4206-B82F-83E846FC2443} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {A885C9E5-BC26-49A4-A01E-F202067084F5} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {B9C7CE32-DA91-43C2-B7E9-0E9AAFC675CD} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {BEE71CD1-E2E7-4B19-B9D3-6920F5C9DBE7} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {C5334550-FA53-4631-A906-FF6D32AD4411} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {CDEB261D-C6C4-4370-9B7A-33E50BDFED74} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {CFF4DB9B-135F-47c0-9269-B4C6572FD61A} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {DB2DF2D1-E683-40DA-96B9-A1A7396332AE} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
SearchScopes: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> {EAF19D11-7800-4E47-A37B-02089180ECC0} URL = hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll [2015-11-04] (IObit)
BHO: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll [2012-04-27] (RealPlayer)
BHO: No Name -> {3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C} -> No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-04-04] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-07-12] (AVAST Software)
BHO: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-04-01] (IObit)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-04-04] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKLM - No Name - !{8dcb7100-df86-4384-8842-8fa844297b3f} - No File
Toolbar: HKLM - No Name - !{eec0f710-38b5-4aba-99bf-ec87564a4e13} - No File
Toolbar: HKLM - No Name - !{F9639E4A-801B-4843-AEE3-03D9DA199E77} - No File
Toolbar: HKLM - No Name - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
Toolbar: HKU\S-1-5-21-2460206527-1493759754-90791392-1000 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
FireFox:
========
FF ProfilePath: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default
FF DefaultSearchEngine: omiga-plus
FF DefaultSearchUrl: hxxps://www.google.com/search
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: omiga-plus
FF Keyword.URL: hxxps://www.google.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-13] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2010-01-12] (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX -> C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Users\nela\Desktop\Picasa3\npPicasa3.dll [No File]
FF Plugin: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-04-04] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll [2012-03-29] ( Microsoft Corporation)
FF Plugin: @mywebsearch.com/Plugin -> C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll [No File]
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-10-02] (NVIDIA Corporation)
FF Plugin: @real.com/nppl3260;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpchromebrowserrecordext;version=15.0.3.37 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=15.0.3.37 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=15.0.3.37 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll [2013-12-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2460206527-1493759754-90791392-1000: ubisoft.com/uplaypc -> C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [No File]
FF user.js: detected! => C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\user.js [2015-04-10]
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppl3260.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll [2013-06-30] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nprpjplug.dll [2012-04-27] (RealNetworks, Inc.)
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\askcom.xml [2013-07-05]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\askcomsearch.xml [2013-05-20]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\bingp.xml [2013-05-30]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\funmoods.xml [2014-08-12]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\icqplugin.xml [2015-04-04]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\MyStart Search.xml [2012-09-22]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\omiga-plus.xml [2015-02-12]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\Search_Results.xml [2012-03-31]
FF SearchPlugin: C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\searchplugins\yahoo-zugo.xml [2011-10-27]
FF Extension: (FF Toolbar) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\fftoolbar2014@etech.com [2015-01-23] [not signed]
FF Extension: (WebCake) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\plugins@getwebcake.com.xpi [2013-11-28] [not signed]
FF Extension: (Seznam lištička) - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2014-06-04] [not signed]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010-02-16] [not signed]
FF HKLM\...\Firefox\Extensions: [m3ffxtbr@mywebsearch.com] - C:\Program Files\MyWebSearch\bar\1.bin => not found
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: (RealPlayer Browser Record Plugin) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012-04-27] [not signed]
FF HKLM\...\Firefox\Extensions: [{336D0C35-8A85-403a-B9D2-65C292C39087}] - C:\Program Files\Web Assistant\Firefox => not found
FF HKLM\...\Firefox\Extensions: [{8E9E3331-D360-4f87-8803-52DE43566502}] - C:\Program Files\Web Assistant\Firefox => not found
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-07-12]
FF HKLM\...\Firefox\Extensions: [fftoolbar2014@etech.com] - C:\Users\nela\AppData\Roaming\Mozilla\Firefox\Profiles\rh5m6efv.default\extensions\fftoolbar2014@etech.com
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-07-12]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF HKU\S-1-5-21-2460206527-1493759754-90791392-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [dlnembnfbcpjnepmfjmngjenhhajpdfd] - C:\Program Files\Web Assistant\source.crx <not found>
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-06-29]
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2012-04-27]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-07-12] (AVAST Software)
S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 BirdkissP; C:\ProgramData\Birdkiss\Birdkiss.exe [418688 2016-06-07] ()
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [387616 2009-04-19] ()
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [694784 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 InterHop; C:\Program Files\InterHop\InterHop.exe [409320 2016-09-21] ()
R2 iSafeService; C:\Program Files\Elex-tech\YAC\iSafeSvc.exe [118048 2016-05-23] (Elex do Brasil Participações Ltda)
S2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2904864 2015-06-02] (IObit)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S3 npggsvc; C:\Windows\system32\GameMon.des [3743800 2010-04-04] (INCA Internet Co., Ltd.) [File not signed]
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [178720 2009-04-19] ()
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2013-07-06] ()
R2 qkseeService; C:\Program Files\qksee\qkseeSvc.exe [690904 2016-04-27] (Qksee Pvt Ltd.)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [2114384 2015-12-15] (Crawler Group, LLC)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 adusbser; C:\Windows\System32\DRIVERS\adusbser.sys [93440 2006-10-23] (AnyDATA Corporation)
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [34008 2016-07-12] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [35096 2016-07-12] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [91680 2016-07-12] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [91232 2016-07-12] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [60424 2016-07-12] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [816304 2016-07-12] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [438296 2016-07-13] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [118152 2016-07-12] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [224616 2016-08-05] (AVAST Software)
S3 CrystalSysInfo; C:\Program Files\MediaCoder\SysInfo.sys [15152 2007-09-25] ()
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [21664 2004-10-25] (EnTech Taiwan) [File not signed]
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R1 iSafeKrnl; C:\Program Files\Elex-tech\YAC\iSafeKrnl.sys [227776 2016-05-23] (Elex do Brasil Participações Ltda)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [50280 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files\Elex-tech\YAC\iSafeKrnlKit.sys [97912 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlMon; C:\Program Files\Elex-tech\YAC\iSafeKrnlMon.sys [45032 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files\Elex-tech\YAC\iSafeKrnlR3.sys [73232 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [59152 2016-05-19] (Elex do Brasil Participações Ltda)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
R1 SCDEmu; C:\Windows\system32\Drivers\SCDEmu.sys [114376 2013-10-23] (Power Software Ltd)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [320120 2014-11-14] (Duplex Secure Ltd.)
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] () [File not signed]
R3 VIAHdAudAddService; C:\Windows\System32\drivers\viahduaa.sys [1056256 2009-06-02] (VIA Technologies, Inc.)
U3 azzh22jc; C:\Windows\system32\Drivers\azzh22jc.sys [0 ] (Advanced Micro Devices) <==== ATTENTION (zero byte File/Folder)
S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]
S3 XDva401; \??\C:\Windows\system32\XDva401.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-23 14:50 - 2016-09-23 14:51 - 00036523 _____ C:\Users\nela\Desktop\FRST.txt
2016-09-23 14:49 - 2016-09-23 14:50 - 00000000 ____D C:\FRST
2016-09-23 14:48 - 2016-09-23 14:48 - 00112640 _____ (forum.viry.cz) C:\Users\nela\Desktop\FRSTLauncher.exe
2016-09-23 14:45 - 2016-09-23 14:45 - 01753088 _____ (Farbar) C:\Users\nela\Desktop\FRST.exe
2016-09-21 19:09 - 2016-09-21 19:10 - 00000000 ____D C:\Program Files\InterHop
2016-09-13 22:20 - 2016-09-13 22:20 - 20448960 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2016-09-12 19:33 - 2016-09-12 19:33 - 00852405 _____ C:\Users\nela\Downloads\Opravene_zaznamove_archy_DT_podzim_2016.zip
2016-09-12 15:13 - 2016-09-12 15:13 - 00168880 _____ C:\Users\nela\Downloads\skener_sharp@zs-klokanek.eu_20160516_095303 (1).pdf
2016-09-12 15:07 - 2016-09-12 15:07 - 00277409 _____ C:\Users\nela\Downloads\prihlaska2016.pdf
2016-09-12 12:54 - 2016-09-12 12:54 - 00054262 _____ C:\Users\nela\Downloads\Protokol_o_vysledcich_SC_MZ_podzim_2016.zip
2016-09-02 17:10 - 2016-09-02 17:10 - 00192774 _____ C:\Users\nela\Downloads\CJL_podzim_2016_DT.pdf
2016-08-29 17:50 - 2016-08-29 17:50 - 70757971 _____ C:\Users\nela\Downloads\maturita-anglictina-didakticky-test-poslech-2016-jaro.zip
2016-08-27 13:36 - 2016-08-27 13:36 - 00366094 _____ C:\Users\nela\Downloads\kriteria_prijimaciho_rizeni_3kolo_2016_2017.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-09-23 14:20 - 2015-12-01 18:01 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-09-23 12:42 - 2014-04-16 20:15 - 00000000 ____D C:\Program Files\Opera
2016-09-23 11:35 - 2016-06-07 19:28 - 00000000 _____ C:\Users\Public\Documents\report.dat
2016-09-23 11:35 - 2013-06-08 14:20 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2016-09-23 11:35 - 2012-04-27 11:25 - 00000932 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-09-23 11:33 - 2016-04-27 13:57 - 00000000 ____D C:\Program Files\qksee
2016-09-23 11:33 - 2012-01-01 10:41 - 00000000 ____D C:\ProgramData\NVIDIA
2016-09-23 11:33 - 2010-07-22 19:25 - 00000000 ____D C:\Program Files\TeamViewer
2016-09-23 11:33 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-21 19:18 - 2014-03-29 14:50 - 00000000 ____D C:\ProgramData\Spyware Terminator
2016-09-18 20:41 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-18 20:41 - 2009-07-14 06:34 - 00015152 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-18 20:31 - 2015-11-04 21:11 - 00000000 ____D C:\ProgramData\ProductData
2016-09-18 20:30 - 2015-07-15 20:19 - 00000958 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2016-09-13 22:21 - 2013-03-19 17:49 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2016-09-13 22:21 - 2011-09-24 16:03 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2016-09-13 22:20 - 2009-12-31 20:08 - 00000000 ____D C:\Windows\system32\Macromed
2016-09-12 15:10 - 2016-02-10 21:13 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-08-30 13:56 - 2010-02-01 16:30 - 00000000 ____D C:\Users\nela\AppData\Roaming\Skype
2016-08-30 12:55 - 2016-06-14 15:15 - 00000000 ___RD C:\Program Files\Skype
2016-08-30 12:55 - 2010-02-01 16:28 - 00000000 ____D C:\ProgramData\Skype
==================== Files in the root of some directories =======
2012-09-22 12:11 - 2012-09-22 12:11 - 1662242 _____ () C:\Program Files\EM3patch1.zip
2011-06-03 15:49 - 2011-10-26 19:59 - 0087608 _____ () C:\Users\nela\AppData\Roaming\inst.exe
2011-06-03 15:49 - 2011-10-26 19:59 - 0007887 _____ () C:\Users\nela\AppData\Roaming\pcouffin.cat
2011-06-03 15:49 - 2011-10-26 19:59 - 0001144 _____ () C:\Users\nela\AppData\Roaming\pcouffin.inf
2011-06-03 15:50 - 2011-10-26 19:59 - 0000033 _____ () C:\Users\nela\AppData\Roaming\pcouffin.log
2011-06-03 15:49 - 2011-10-26 19:59 - 0047360 _____ (VSO Software) C:\Users\nela\AppData\Roaming\pcouffin.sys
2011-06-03 15:50 - 2011-10-10 22:56 - 0000668 _____ () C:\Users\nela\AppData\Roaming\vso_ts_preview.xml
2010-07-20 17:25 - 2010-07-26 12:49 - 0000600 _____ () C:\Users\nela\AppData\Roaming\winscp.rnd
2010-07-22 00:55 - 2016-01-31 18:03 - 0096256 _____ () C:\Users\nela\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-08-05 15:26 - 2012-08-05 15:26 - 0027520 _____ () C:\Users\nela\AppData\Local\dt.dat
2016-01-20 01:06 - 2016-01-20 01:06 - 0004415 _____ () C:\Users\nela\AppData\Local\recently-used.xbel
2010-07-12 11:22 - 2010-07-12 11:22 - 0007609 _____ () C:\Users\nela\AppData\Local\Resmon.ResmonCfg
2012-09-21 20:20 - 2012-09-21 20:20 - 0000057 _____ () C:\ProgramData\Ament.ini
2010-02-04 14:52 - 2011-10-26 20:13 - 0004773 _____ () C:\ProgramData\hpzinstall.log
2015-11-30 11:22 - 2016-01-08 14:36 - 0000074 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Users\nela\jagex_runescape_preferences.dat
C:\Users\nela\jagex_runescape_preferences2.dat
Some files in TEMP:
====================
C:\Users\nela\AppData\Local\Temp\ASCSetup_9871384.exe
C:\Users\nela\AppData\Local\Temp\lowproc.exe
C:\Users\nela\AppData\Local\Temp\MSETUP4.EXE
C:\Users\nela\AppData\Local\Temp\rnsetup0.exe
C:\Users\nela\AppData\Local\Temp\rnsetup1.exe
C:\Users\nela\AppData\Local\Temp\rnsetup2.exe
C:\Users\nela\AppData\Local\Temp\SkypeSetup.exe
C:\Users\nela\AppData\Local\Temp\stubhelper.dll
C:\Users\nela\AppData\Local\Temp\vywa8pa1.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\system32\Macromed\Flash\FlashUtil32_23_0_0_162_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{AAF13F04-653E-4678-9CE3-23660447CBC9}.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: AVG Internet Security 2012 (Disabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AS: AVG Internet Security 2012 (Disabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: AVG Internet Security 2012 (Disabled) {621CC794-9486-F902-D092-0484E8EA828B}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\nela\Desktop" je 165801 MB.
***** Startup Programs *****
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount
"C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon
"C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ
"C:\Program Files\ICQ7.5\ICQ.exe" silent loginmode=4 [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
"C:\Program Files\QuickTime\QTTask.exe" -atboottime [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\seznam-listicka-distribuce
"C:\Program Files\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate [x]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
"C:\hry\Steam\Steam.exe" -silent [x]
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================