Prosim o kontrolu

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Prosim o kontrolu

Příspěvekod Marcelko69 » 13 lis 2015 19:45

Už nejakú dobu sa mi notebook prehrieva prosim o kontrolu logo.
za kontrolu vopred ďakujem.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:41:10, on 13.11.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\furst\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\furst\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\furst\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\furst\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Users\furst\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: GameRanger.lnk = C:\Users\furst\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: IhPul - tsvr.com - C:\Users\furst\AppData\Roaming\TSv\TSvr.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mobile Partner. OUC (Mobile Partner. RunOuc) - Unknown owner - C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: Wifi Man Service (wifimansvc) - Unknown owner - C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: WinZiper service (winzipersvc) - Taiwan Shui Mu Chih Ching Technology Limited - C:\Program Files (x86)\WinZipper\winzipersvc.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10884 bytes

Reklama
Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod jerabina » 13 lis 2015 23:57

Ahoj, vítej na fóru PC-HELP!

Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.

- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.

===================================================

Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

===================================================

Stáhni AdwCleaner (by Xplode)

Ulož si ho na svojí plochu
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Prohledat-Scan“
Po skenu se objeví log ( jinak je uložen systémovem disku jako AdwCleaner[R?].txt), jeho obsah sem celý vlož.

===================================================

Stáhni si Malwarebytes' Anti-Malware
- Při instalaci odeber zatržítko u „Povolit bezplatnou zkušební verzi Malwarebytes' Anti-Malware Premium“
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a klikni na Skenovat nyní a
- po proběhnutí programu se ti objeví hláška vpravo dole tak klikni na Kopírovat do schránky a a vlož sem celý log.

- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).

Pokud budou problémy , spusť v nouz. režimu.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 14 lis 2015 00:37

AdwCleaner log:

# AdwCleaner v5.020 - Logfile created 14/11/2015 at 00:18:16
# Updated 13/11/2015 by Xplode
# Database : 2015-11-13.3 [Server]
# Operating system : Windows 10 Home (x64)
# Username : furst - DESKTOP-QCH9SSA
# Running from : C:\Users\furst\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : winzipersvc
Service Found : IhPul

***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\globalUpdate
Folder Found : C:\Program Files (x86)\predm
Folder Found : C:\Program Files (x86)\WinZipper
Folder Found : C:\Program Files (x86)\Elex-tech
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
Folder Found : C:\Users\furst\AppData\Local\globalUpdate
Folder Found : C:\Users\furst\AppData\Roaming\eCyber
Folder Found : C:\Users\furst\AppData\Roaming\WinZipper
Folder Found : C:\Users\furst\AppData\Roaming\Elex-tech
Folder Found : C:\Users\furst\AppData\Roaming\RHEng
Folder Found : C:\Users\furst\AppData\Roaming\TSv

***** [ Files ] *****

File Found : C:\WINDOWS\SysNative\log\iSafeKrnlCall.log

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : runTask
Task Found : updateTask

***** [ Registry ] *****

Key Found : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
Key Found : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
Key Found : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
Key Found : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinZipper
Key Found : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
Key Found : HKLM\SOFTWARE\Classes\WinZipper.001
Key Found : HKLM\SOFTWARE\Classes\WinZipper.7z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.arj
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.bzip2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cab
Key Found : HKLM\SOFTWARE\Classes\WinZipper.cpio
Key Found : HKLM\SOFTWARE\Classes\WinZipper.deb
Key Found : HKLM\SOFTWARE\Classes\WinZipper.dmg
Key Found : HKLM\SOFTWARE\Classes\WinZipper.fat
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.gzip
Key Found : HKLM\SOFTWARE\Classes\WinZipper.hfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.iso
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lha
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzh
Key Found : HKLM\SOFTWARE\Classes\WinZipper.lzma
Key Found : HKLM\SOFTWARE\Classes\WinZipper.ntfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.rpm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.squashfs
Key Found : HKLM\SOFTWARE\Classes\WinZipper.swm
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.taz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tbz2
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tgz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.tpz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.txz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.vhd
Key Found : HKLM\SOFTWARE\Classes\WinZipper.wim
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xar
Key Found : HKLM\SOFTWARE\Classes\WinZipper.xz
Key Found : HKLM\SOFTWARE\Classes\WinZipper.z
Key Found : HKLM\SOFTWARE\Classes\WinZipper.zip
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{4F622628-7632-4B28-B184-D7BA0CA3273B}
Key Found : HKCU\Software\GlobalUpdate
Key Found : HKCU\Software\DAILYPCCLEAN
Key Found : HKLM\SOFTWARE\GlobalUpdate
Key Found : HKLM\SOFTWARE\hdcode
Key Found : HKLM\SOFTWARE\winzipersvc
Key Found : HKLM\SOFTWARE\Elex-tech
Key Found : HKLM\SOFTWARE\TSv
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gpuminer
Key Found : HKU\.DEFAULT\Software\Elex-tech
Key Found : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer
Key Found : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
Key Found : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\oursurfing.com

***** [ Web browsers ] *****

[C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : adblock-chrome.en.softonic.com
[C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : omniboxes
[C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.delta-homes.com/?type=hp&ts= ... XXW3815F6Y
[C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://www.omniboxes.com/?type=hp&ts=14 ... XXW3815F6Y
[C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Found : hxxp://www.omniboxes.com/webfavicon.ico

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [5420 bytes] ##########

Malwarebytes' Anti-Malware log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Dátum kontroly: 14.11.2015
Čas kontroly: 0:20
Protokol:
Správca: Áno

Verzia: 2.2.0.1024
Dazabáza malware: v2015.11.13.08
Databáza rootkitov: v2015.11.13.01
Licencia: Bezplatná verzia
Ochrana pred škodlivým softvérom: Vypnuté
Ochrana pred škodlivými webstránkami: Vypnuté
Vlastná ochrana: Vypnuté

OS: Windows 10
CPU: x64
Súborový systém: NTFS
Používateľ: furst

Typ kontroly: Kontrola hrozieb
Výsledok: Dokončená
Skontrolovaných objektov: 364295
Uplynulý čas: 13 min, 47 s

Pamäť: Zapnuté
Pri spustení: Zapnuté
Súborový systém: Zapnuté
Archívy: Zapnuté
Rootkity: Vypnuté
Heuristika: Zapnuté
PUP: Zapnuté
PUM: Zapnuté

Procesy: 0
(Žiadne škodlivé položky neboli zistené)

Moduly: 0
(Žiadne škodlivé položky neboli zistené)

Kľúče databázy Registry: 0
(Žiadne škodlivé položky neboli zistené)

Hodnoty databázy Registry: 0
(Žiadne škodlivé položky neboli zistené)

Údaj databázy Registry: 0
(Žiadne škodlivé položky neboli zistené)

Priečinky: 0
(Žiadne škodlivé položky neboli zistené)

Súbory: 0
(Žiadne škodlivé položky neboli zistené)

Fyzické sektory: 0
(Žiadne škodlivé položky neboli zistené)


(end)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Orcus » 14 lis 2015 08:40

- Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce“
- Klikni na „ Smazat“
- Program provede opravu, po automatickém restartu neukáže log (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

====================================================

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)


- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

====================================================

Stáhni si RogueKiller
32bit.:
http://www.sur-la-toile.com/RogueKiller/RogueKiller.exe
64bit.:
http://www.sur-la-toile.com/RogueKiller ... lerX64.exe
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- Počkej až skončí Prescan -vyhledávání škodlivých procesů.
- Potom klikni na „Prohledat“.
- Program skenuje procesy PC. Po proskenování klikni na „Zpráva“celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 14 lis 2015 12:21

AdwareCleaner log:

# AdwCleaner v5.020 - Logfile created 14/11/2015 at 11:39:15
# Updated 13/11/2015 by Xplode
# Database : 2015-11-13.3 [Server]
# Operating system : Windows 10 Home (x64)
# Username : furst - DESKTOP-QCH9SSA
# Running from : C:\Users\furst\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : winzipersvc
[-] Service Deleted : IhPul

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\globalUpdate
[-] Folder Deleted : C:\Program Files (x86)\predm
[-] Folder Deleted : C:\Program Files (x86)\WinZipper
[-] Folder Deleted : C:\Program Files (x86)\Elex-tech
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZipper
[-] Folder Deleted : C:\Users\furst\AppData\Local\globalUpdate
[-] Folder Deleted : C:\Users\furst\AppData\Roaming\eCyber
[-] Folder Deleted : C:\Users\furst\AppData\Roaming\WinZipper
[-] Folder Deleted : C:\Users\furst\AppData\Roaming\Elex-tech
[-] Folder Deleted : C:\Users\furst\AppData\Roaming\RHEng
[-] Folder Deleted : C:\Users\furst\AppData\Roaming\TSv

***** [ Files ] *****

[-] File Deleted : C:\WINDOWS\SysNative\log\iSafeKrnlCall.log

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : runTask
[-] Task Deleted : updateTask

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZipper
[-] Key Deleted : HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZipper
[-] Key Deleted : HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\WinZipper
[-] Key Deleted : HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinZipper
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WdsManPro
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.001
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.7z
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.arj
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.bz2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.bzip2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.cab
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.cpio
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.deb
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.dmg
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.fat
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.gz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.gzip
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.hfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.iso
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.lha
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.lzh
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.lzma
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.ntfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.rar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.rpm
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.squashfs
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.swm
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.tar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.taz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.tbz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.tbz2
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.tgz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.tpz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.txz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.vhd
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.wim
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.xar
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.xz
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.z
[-] Key Deleted : HKLM\SOFTWARE\Classes\WinZipper.zip
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4F622628-7632-4B28-B184-D7BA0CA3273B}
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\hdcode
[-] Key Deleted : HKLM\SOFTWARE\winzipersvc
[-] Key Deleted : HKLM\SOFTWARE\Elex-tech
[-] Key Deleted : HKLM\SOFTWARE\TSv
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winzipper
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\gpuminer
[-] Key Deleted : HKU\.DEFAULT\Software\Elex-tech
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Installer
[-] Key Deleted : HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\oursurfing.com

***** [ Web browsers ] *****

[-] [C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : adblock-chrome.en.softonic.com
[-] [C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : omniboxes
[-] [C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.delta-homes.com/?type=hp&ts= ... XXW3815F6Y
[-] [C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.omniboxes.com/?type=hp&ts=14 ... XXW3815F6Y
[-] [C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Deleted : hxxp://www.omniboxes.com/webfavicon.ico

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5968 bytes] ##########

Junkware Removal Tool log:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.4 (09.28.2015:1)
OS: Windows 10 Home x64
Ran by furst on 14.11.2015 at 11:43:21,68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks



~~~ Registry Values



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat



~~~ Folders



~~~ Chrome


[C:\Users\furst\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\furst\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\furst\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\furst\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
bgjpfhpjcgdppjbgnpnjllokbmcdllig,
blmojkbhnkkphngknkmgccmlenfaelkd,
olfeabkoenfaoljndfecamgilllcpiak
]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.11.2015 at 11:45:43,19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

RogueKiller1 log:

RogueKiller V10.11.5.0 (x64) [Nov 9 2015] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : furst [Administrator]
Started from : C:\Users\furst\Desktop\RogueKillerX64.exe
Mode : Delete -- Date : 11/14/2015 12:11:51

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 352499b3b854ba0da9828f5f5d323655
[BSP] dbcf146c463bbc7c9a28454074d03841 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953303 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1952573440 | Size: 463 MB
User = LL1 ... OK
User = LL2 ... OK

RogueKiller2 log:

RogueKiller V10.11.5.0 (x64) [Nov 9 2015] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : furst [Administrator]
Started from : C:\Users\furst\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 11/14/2015 12:17:57

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 352499b3b854ba0da9828f5f5d323655
[BSP] dbcf146c463bbc7c9a28454074d03841 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953303 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1952573440 | Size: 463 MB
User = LL1 ... OK
User = LL2 ... OK

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod jerabina » 14 lis 2015 18:48

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)
- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 14 lis 2015 20:02

RogueKiller log:

RogueKiller V10.11.5.0 (x64) [Nov 9 2015] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Website : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : furst [Administrator]
Started from : C:\Users\furst\Desktop\RogueKillerX64.exe
Mode : Delete -- Date : 11/14/2015 19:43:29

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ Hosts File : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhostDeleted

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 352499b3b854ba0da9828f5f5d323655
[BSP] dbcf146c463bbc7c9a28454074d03841 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953303 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1952573440 | Size: 463 MB
User = LL1 ... OK
User = LL2 ... OK

Zoek log:

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by furst on 14.11.2015 at 19:44:20,48.
Microsoft Windows 10 Home 10.0.10240 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\furst\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

14.11.2015 19:46:15 Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\COMMON~1\Merge Modules deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\Users\furst\AppData\Local\62379AB5-1764-4881-A1B-945AFCBCF754 deleted successfully
C:\Users\furst\AppData\Local\NetworkTiles deleted successfully
C:\Users\furst\AppData\Local\Opera Software deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== Deleting Files \ Folders ======================

C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\furst\AppData\Local\Daltron.exe.config deleted
"C:\Users\furst\AppData\Local\LumaEmu" deleted

==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
lifbcibllhkdhoafpjfnlhfpfgnpldfl - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx[12.10.2015 02:31]

Context - furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aalnjolghjkkogicompabhhbbkljnlka
Vichrome - furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\gghkfhpblkcmlkmpcpgaajbbiikbhpdi
AdBlock - furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom
Skype Click to Call - furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl
MyPermissions Cleaner - furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi

==== Chromium Fix ======================

C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage deleted successfully
C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_c.betrad.com_0.localstorage-journal deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://www.google.com"
"Start Page Redirect Cache"="http://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Bar"="http://www.google.com"
"Start Page Redirect Cache"="http://www.google.com"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page Redirect Cache"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Search Bar"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page Redirect Cache"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02"

==== Reset Google Chrome ======================

C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\furst\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\furst\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Profiles found

==== Empty Chrome Cache ======================

C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=322 folders=578 1144566726 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\furst\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on 14.11.2015 at 19:57:00,79 ======================

HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:58:55, on 14.11.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)


Boot mode: Normal

Running processes:
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Users\furst\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
C:\Users\furst\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\furst\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\furst\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [uTorrent] "C:\Users\furst\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: GameRanger.lnk = C:\Users\furst\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HWDeviceService64.exe - Unknown owner - C:\ProgramData\DatacardService\HWDeviceService64.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo EasyPlus Hotspot - Lenovo - C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe
O23 - Service: Mobile Partner. OUC (Mobile Partner. RunOuc) - Unknown owner - C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: Wifi Man Service (wifimansvc) - Unknown owner - C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9878 bytes

informácie o probléme: začal sa mi notebook prehrievať aj pri základných činnostiach čo predtm nerobil su to cca dva týždne potom som si skontroloval notebook cez program malwarebytes našlo to cca 2342 detekovaných súborov z toho asi 800 bolo CPU miner myslel som si teda že problém bol vyriešený ale prehrievanie ostalo tak som sa obrátil na toto fórum a od vtedy robím všetko tak ako mi je napísane problém však naďalej pretrváva

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Orcus » 14 lis 2015 20:11

Vyčisti notebook od prachu.

Stáhni HWMonitor a nainstaluj jej.
- Spusť, případně proveď update pokud bude potřeba, a uveď PC do plného zatížení na alespoň 15 minut, abychom mohli vidět maximální teploty, kterých HW dosahuje.
- Udělej screenshot teplot a ten sem vlož, tak jak je popsáno v návodu k tomuto fóru.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.

Pokud budou problémy , spusť v nouz. režimu.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 14 lis 2015 21:18

tu je obrázok s teplotami

Obrázek

program Combofix bohužial nie je kompatibilný s mojou verziou operačného systému-windows10.

Obrázek

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod jerabina » 14 lis 2015 23:45

Chybička se stala, omlouváme se.

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit Farbar Recovery Scan Tool (FRST)
32bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
64bit.:
http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
a ulož jej na plochu. ,pak spusť FRST jako správce
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 15 lis 2015 00:09

FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-11-2015
Ran by furst (administrator) on DESKTOP-QCH9SSA (15-11-2015 00:01:04)
Running from C:\Users\furst\Desktop
Loaded Profiles: furst (Available Profiles: furst)
Platform: Windows 10 Home (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
() C:\ProgramData\DataCardService\HWDeviceService64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Windows\syswow64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Windows\syswow64\PnkBstrB.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DataCardService\DCSHelper.exe
() C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945672 2015-09-04] (Synaptics Incorporated)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6346312 2013-03-15] (Realtek semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14021336 2015-06-18] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597040 2015-10-06] (Oracle Corporation)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3011152 2015-11-10] (Valve Corporation)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\Run: [uTorrent] => C:\Users\furst\AppData\Roaming\uTorrent\uTorrent.exe [1822048 2015-10-24] (BitTorrent Inc.)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [55349888 2015-09-04] (Skype Technologies S.A.)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4468056 2015-06-18] (Disc Soft Ltd)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7935904 2015-10-23] (SUPERAntiSpyware)
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\MountPoints2: {5aba777e-5ccd-11e5-b624-28d2444e0b3a} - "F:\SETUP.EXE"
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\MountPoints2: {95b51578-86ea-11e5-b63c-28d2444e0b3a} - "H:\SETUP.EXE"
HKU\S-1-5-21-1508215794-3306958152-728342842-1001\...\MountPoints2: {d9665364-6198-11e5-b628-28d2444e0b3a} - "G:\SETUP.EXE"
Startup: C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk [2015-11-12]
ShortcutTarget: GameRanger.lnk -> C:\Users\furst\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6cfb2f53-bcca-4c6e-9cc8-10e18008e129}: [DhcpNameServer] 192.168.200.11 192.168.200.12
Tcpip\..\Interfaces\{cf97275a-8137-46ad-a9be-035a126e84d3}: [DhcpNameServer] 7.254.254.254
Tcpip\..\Interfaces\{f3761e60-49cc-4a3a-aa22-9104ac189731}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID= ... DD807BB0F0
SearchScopes: HKLM-x32 -> DefaultScope {425ED333-6083-428a-92C9-0CFC28B9D1BF} URL =
SearchScopes: HKU\S-1-5-21-1508215794-3306958152-728342842-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1508215794-3306958152-728342842-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\ssv.dll [2015-10-29] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\jp2ssv.dll [2015-10-29] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-11] ()
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-11] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\dtplugin\npDeployJava1.dll [2015-10-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.65.2 -> C:\Program Files (x86)\Java\jre1.8.0_65\bin\plugin2\npjp2.dll [2015-10-29] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-02] (Google Inc.)
StartMenuInternet: firefox.exe - firefox.exe

Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/?clid=13415
CHR StartupUrls: Default -> "hxxps://www.google.sk/","hxxp://www.delta-homes.com/?type=hp&ts=1444665030&z=6fbc913dbf4bc3b47e6bee2g7z7z5z1m0e7g3e8qfz&from=wpm07163&uid=ST1000LM014-SSHD-8GB_W3815F6YXXXXW3815F6Y","hxxp://www.omniboxes.com/?type=hp&ts=1447150091&z=e0a2d21d7e17fc6ba7e678fgbz5z8m8g2w0e3e7tez&from=wpm07163&uid=ST1000LM014-SSHD-8GB_W3815F6YXXXXW3815F6Y"
CHR Profile: C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Context) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aalnjolghjkkogicompabhhbbkljnlka [2015-11-14]
CHR Extension: (Prezentácie Google) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-14]
CHR Extension: (Dokumenty Google) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-14]
CHR Extension: (Disk Google) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-14]
CHR Extension: (YouTube) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-14]
CHR Extension: (Google Search) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-14]
CHR Extension: (Tabuľky Google) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-14]
CHR Extension: (Vichrome) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\gghkfhpblkcmlkmpcpgaajbbiikbhpdi [2015-11-14]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-14]
CHR Extension: (AdBlock) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-11-14]
CHR Extension: (Skype Click to Call) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-11-14]
CHR Extension: (MyPermissions Cleaner) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2015-11-14]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-14]
CHR Extension: (Gmail) - C:\Users\furst\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-14]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]

Opera:
=======
OPR Extension: (No Name) - C:\Users\furst\AppData\Roaming\Opera Software\Opera Stable\Extensions\aalnjolghjkkogicompabhhbbkljnlka [2015-10-06]
OPR Extension: (No Name) - C:\Users\furst\AppData\Roaming\Opera Software\Opera Stable\Extensions\gghkfhpblkcmlkmpcpgaajbbiikbhpdi [2015-10-07]
OPR Extension: (No Name) - C:\Users\furst\AppData\Roaming\Opera Software\Opera Stable\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2015-10-06]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-12] (NVIDIA Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [351120 2015-07-17] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo)
S2 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [657504 2012-11-01] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-12] (NVIDIA Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2015-11-12] ()
R2 PnkBstrB; C:\WINDOWS\SysWOW64\PnkBstrB.exe [202040 2015-11-13] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [246472 2015-09-04] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [800208 2015-08-28] (Tunngle.net GmbH)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [52968 2015-07-06] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 wifimansvc; C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe [605696 2012-11-10] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 a016bus; C:\Windows\System32\drivers\a016bus.sys [109096 2008-01-18] (MCCI Corporation)
S3 a016mgmt; C:\Windows\System32\drivers\a016mgmt.sys [130600 2008-01-18] (MCCI Corporation)
S3 a016obex; C:\Windows\System32\drivers\a016obex.sys [125480 2008-01-18] (MCCI Corporation)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-09-17] (Disc Soft Ltd)
S3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-02-23] (Disc Soft Ltd)
S3 ggsomc; C:\Windows\System32\drivers\ggsomc.sys [30424 2014-08-11] (Sony Mobile Communications)
R3 L1C; C:\Windows\System32\drivers\L1C62x64.sys [128200 2013-04-26] (Qualcomm Atheros Co., Ltd.)
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3354384 2015-07-10] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.)
S3 NPF; C:\Windows\SysWOW64\drivers\NPF.sys [35344 2012-09-22] (CACE Technologies, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-12] (NVIDIA Corporation)
S3 NVSWCFilter; C:\Windows\System32\drivers\nvswcfilter.sys [19616 2015-06-13] (Windows (R) Win 7 DDK provider)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-11] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243272 2013-03-15] (Realtek Semiconductor Corp.)
S3 s0016bus; C:\Windows\System32\drivers\s0016bus.sys [115240 2008-05-16] (MCCI Corporation)
S3 s0016mgmt; C:\Windows\System32\drivers\s0016mgmt.sys [137256 2008-05-16] (MCCI Corporation)
S3 s0016obex; C:\Windows\System32\drivers\s0016obex.sys [136744 2008-05-16] (MCCI Corporation)
S3 s0016unic; C:\Windows\System32\drivers\s0016unic.sys [151592 2008-05-16] (MCCI Corporation)
S3 s0017bus; C:\Windows\System32\drivers\s0017bus.sys [113704 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\drivers\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\drivers\s0017obex.sys [128552 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\drivers\s0017unic.sys [145960 2008-10-21] (MCCI Corporation)
S3 s1018bus; C:\Windows\System32\drivers\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\Windows\System32\drivers\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\Windows\System32\drivers\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\Windows\System32\drivers\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
S3 s1029bus; C:\Windows\System32\drivers\s1029bus.sys [116264 2009-05-25] (MCCI Corporation)
S3 s1029mgmt; C:\Windows\System32\drivers\s1029mgmt.sys [139304 2009-05-25] (MCCI Corporation)
S3 s1029obex; C:\Windows\System32\drivers\s1029obex.sys [135208 2009-05-25] (MCCI Corporation)
S3 s1029unic; C:\Windows\System32\drivers\s1029unic.sys [151592 2009-05-25] (MCCI Corporation)
S3 s1039bus; C:\Windows\System32\drivers\s1039bus.sys [127600 2010-03-15] (MCCI Corporation)
S3 s1039mgmt; C:\Windows\System32\drivers\s1039mgmt.sys [141424 2010-03-15] (MCCI Corporation)
S3 s1039obex; C:\Windows\System32\drivers\s1039obex.sys [137328 2010-03-15] (MCCI Corporation)
S3 s1039unic; C:\Windows\System32\drivers\s1039unic.sys [158320 2010-03-15] (MCCI Corporation)
S3 s916bus; C:\Windows\System32\drivers\s916bus.sys [108072 2007-11-02] (MCCI Corporation)
S3 s916mgmt; C:\Windows\System32\drivers\s916mgmt.sys [130088 2007-11-02] (MCCI Corporation)
S3 s916obex; C:\Windows\System32\drivers\s916obex.sys [124968 2007-11-02] (MCCI Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 se3ebus; C:\Windows\System32\drivers\se3ebus.sys [107784 2007-04-10] (MCCI Corporation)
S3 se3emgmt; C:\Windows\System32\drivers\se3emgmt.sys [126216 2007-04-10] (MCCI Corporation)
S3 se3eobex; C:\Windows\System32\drivers\se3eobex.sys [123144 2007-04-10] (MCCI Corporation)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [214016 2015-07-10] (Microsoft Corporation)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [42184 2015-09-04] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [42696 2015-09-04] (Synaptics Incorporated)
R3 tap0901t; C:\Windows\System32\drivers\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-10-02] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [146584 2015-10-02] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-15 00:01 - 2015-11-15 00:02 - 00022266 _____ C:\Users\furst\Desktop\FRST.txt
2015-11-15 00:00 - 2015-11-15 00:01 - 00000000 ____D C:\FRST
2015-11-15 00:00 - 2015-11-15 00:00 - 02198528 _____ (Farbar) C:\Users\furst\Downloads\FRST64.exe
2015-11-15 00:00 - 2015-11-15 00:00 - 02198528 _____ (Farbar) C:\Users\furst\Desktop\FRST64.exe
2015-11-14 23:03 - 2015-11-14 23:03 - 00000000 ____D C:\Users\furst\AppData\Local\NetworkTiles
2015-11-14 20:46 - 2015-11-14 20:46 - 05637834 _____ (Swearware) C:\Users\furst\Downloads\ComboFix.exe
2015-11-14 20:23 - 2015-11-14 20:23 - 01199856 _____ ( ) C:\Users\furst\Desktop\hwmonitor_1.28.exe
2015-11-14 20:23 - 2015-11-14 20:23 - 00000975 _____ C:\Users\Public\Desktop\CPUID HWMonitor.lnk
2015-11-14 20:23 - 2015-11-14 20:23 - 00000000 ____D C:\Program Files\CPUID
2015-11-14 20:19 - 2015-11-14 20:19 - 01199856 _____ ( ) C:\Users\furst\Downloads\hwmonitor_1.28.exe
2015-11-14 19:58 - 2015-11-14 19:58 - 00009879 _____ C:\Users\furst\Desktop\hijackthis.log
2015-11-14 19:57 - 2015-11-14 19:57 - 00006418 _____ C:\Users\furst\Desktop\zoek.txt
2015-11-14 19:56 - 2015-11-14 19:56 - 00016148 _____ C:\WINDOWS\system32\DESKTOP-QCH9SSA_furst_HistoryPrediction.bin
2015-11-14 19:55 - 2015-11-14 19:44 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2015-11-14 19:46 - 2015-11-14 19:57 - 00006420 _____ C:\zoek-results.log
2015-11-14 19:44 - 2015-11-14 19:54 - 00000000 ____D C:\zoek_backup
2015-11-14 19:44 - 2015-11-14 19:44 - 00002590 _____ C:\Users\furst\Desktop\rougeu tento.txt
2015-11-14 19:29 - 2015-11-14 19:44 - 01309184 _____ C:\Users\furst\Desktop\zoek.exe
2015-11-14 19:28 - 2015-11-14 19:29 - 01309184 _____ C:\Users\furst\Downloads\zoek.exe
2015-11-14 15:00 - 2015-11-14 15:00 - 00010184 _____ C:\Users\furst\Downloads\moja-analýza-jazyk-C (1).odt
2015-11-14 14:23 - 2015-11-14 14:23 - 00010184 _____ C:\Users\furst\Downloads\moja-analýza-jazyk-C.odt
2015-11-14 12:18 - 2015-11-14 12:18 - 00002572 _____ C:\Users\furst\Desktop\rouge 1.txt
2015-11-14 12:12 - 2015-11-14 12:12 - 00002454 _____ C:\Users\furst\Desktop\rouge.txt
2015-11-14 11:56 - 2015-11-14 19:30 - 00037624 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-11-14 11:45 - 2015-11-14 11:45 - 00001258 _____ C:\Users\furst\Desktop\JRT.txt
2015-11-14 11:36 - 2015-11-14 11:43 - 01801288 _____ (Malwarebytes) C:\Users\furst\Desktop\JRT.exe
2015-11-14 11:35 - 2015-11-14 11:56 - 22939720 _____ C:\Users\furst\Desktop\RogueKillerX64.exe
2015-11-14 11:35 - 2015-11-14 11:35 - 01801288 _____ (Malwarebytes) C:\Users\furst\Downloads\JRT.exe
2015-11-14 10:46 - 2015-11-14 10:46 - 00039912 _____ C:\Users\furst\Downloads\Hodnotenie_studentov_zapoctovka_1.xlsx
2015-11-14 00:34 - 2015-11-14 00:35 - 00001215 _____ C:\Users\furst\Desktop\Nový textový dokument (2).txt
2015-11-14 00:19 - 2015-11-14 11:42 - 00006055 _____ C:\Users\furst\Desktop\Nový textový dokument.txt
2015-11-14 00:18 - 2015-11-14 11:39 - 00000000 ____D C:\AdwCleaner
2015-11-14 00:10 - 2015-11-14 00:10 - 22908888 _____ (Malwarebytes ) C:\Users\furst\Desktop\mbam-setup-2.2.0.1024 (1).exe
2015-11-14 00:10 - 2015-11-14 00:10 - 00001131 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-11-14 00:10 - 2015-11-14 00:10 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-11-14 00:10 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-11-14 00:10 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-11-14 00:10 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-11-14 00:09 - 2015-11-14 00:09 - 22908888 _____ (Malwarebytes ) C:\Users\furst\Downloads\mbam-setup-2.2.0.1024 (1).exe
2015-11-14 00:07 - 2015-11-14 00:18 - 01729536 _____ C:\Users\furst\Desktop\AdwCleaner.exe
2015-11-14 00:06 - 2015-11-14 00:07 - 01729536 _____ C:\Users\furst\Downloads\AdwCleaner.exe
2015-11-14 00:05 - 2015-11-14 00:11 - 00448512 _____ (OldTimer Tools) C:\Users\furst\Desktop\TFC.exe
2015-11-14 00:05 - 2015-11-14 00:05 - 00448512 _____ (OldTimer Tools) C:\Users\furst\Downloads\TFC.exe
2015-11-13 20:50 - 2015-11-13 20:50 - 00000000 ____D C:\Users\furst\Downloads\Inside.Out.2015.BDRip.XviD.CZ-TreZzoR
2015-11-13 20:46 - 2015-11-13 20:46 - 00017411 _____ C:\Users\furst\Downloads\[CzT]V_hlave_Inside_Out_CZ_2015_.torrent
2015-11-13 19:41 - 2015-11-13 19:41 - 00010886 _____ C:\Users\furst\Downloads\hijackthis.log
2015-11-13 19:40 - 2015-11-13 19:40 - 00388608 _____ (Trend Micro Inc.) C:\Users\furst\Desktop\HijackThis.exe
2015-11-13 13:47 - 2015-11-13 13:47 - 00253648 ____N (Microsoft Corporation) C:\WINDOWS\Setup1.exe
2015-11-13 13:47 - 2015-11-13 13:47 - 00077016 _____ (Microsoft Corporation) C:\WINDOWS\ST6UNST.EXE
2015-11-13 13:47 - 2015-11-13 13:47 - 00000000 ____D C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Visustin
2015-11-13 13:47 - 2015-11-13 13:47 - 00000000 ____D C:\Program Files (x86)\Visustin
2015-11-12 21:52 - 2015-11-13 08:31 - 00202040 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2015-11-12 21:52 - 2015-11-12 21:52 - 00066872 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2015-11-12 21:52 - 2015-11-12 21:52 - 00000000 ____D C:\Users\furst\AppData\Local\PunkBuster
2015-11-12 21:45 - 2015-11-14 00:15 - 00000000 ____D C:\Users\furst\Downloads\Call of duty 4 Multiplayer
2015-11-12 21:04 - 2015-11-12 21:30 - 2974820271 ____R C:\Users\furst\Downloads\Call of duty 4 Multiplayer.exe
2015-11-12 21:03 - 2015-11-12 21:03 - 00014753 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_4_Modern_Warfare_Multiplayer_only (1).torrent
2015-11-12 21:00 - 2015-11-12 21:00 - 00022667 _____ C:\Users\furst\Downloads\[CzT]Call_Of_Duty_4_Modern_Warfare_CZ_2007_.torrent
2015-11-12 19:18 - 2015-11-12 19:19 - 05355103 _____ C:\Users\furst\Downloads\visus710.zip
2015-11-12 17:05 - 2015-11-12 17:05 - 00003132 _____ C:\Users\furst\Downloads\Klotton_Michal_23.txt
2015-11-12 17:04 - 2015-11-12 17:04 - 23930968 _____ (SUPERAntiSpyware) C:\Users\furst\Downloads\SUPERAntiSpyware (1).exe
2015-11-12 16:24 - 2015-11-14 16:24 - 00000542 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task e5b8f685-41ea-4a0b-8076-d63b3321bc11.job
2015-11-12 16:24 - 2015-11-14 02:00 - 00000542 _____ C:\WINDOWS\Tasks\SUPERAntiSpyware Scheduled Task 5d7a050d-3a7c-43fc-a6a6-b79674e2c578.job
2015-11-12 16:24 - 2015-11-12 16:24 - 00003782 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task 5d7a050d-3a7c-43fc-a6a6-b79674e2c578
2015-11-12 16:24 - 2015-11-12 16:24 - 00003700 _____ C:\WINDOWS\System32\Tasks\SUPERAntiSpyware Scheduled Task e5b8f685-41ea-4a0b-8076-d63b3321bc11
2015-11-12 16:22 - 2015-11-12 16:22 - 00000000 ____D C:\Users\furst\AppData\Roaming\SUPERAntiSpyware.com
2015-11-12 16:21 - 2015-11-12 16:22 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2015-11-12 16:21 - 2015-11-12 16:21 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2015-11-12 15:58 - 2015-11-12 16:20 - 23930968 _____ (SUPERAntiSpyware) C:\Users\furst\Downloads\SUPERAntiSpyware.exe
2015-11-12 15:15 - 2015-11-12 23:19 - 00000600 _____ C:\Users\furst\AppData\Roaming\winscp.rnd
2015-11-12 15:05 - 2015-11-14 00:20 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-11-12 15:04 - 2015-11-12 15:04 - 22908888 _____ (Malwarebytes ) C:\Users\furst\Downloads\mbam-setup-2.2.0.1024.exe
2015-11-12 14:45 - 2015-11-12 15:48 - 00001008 _____ C:\Users\Public\Desktop\WinSCP.lnk
2015-11-12 14:45 - 2015-11-12 14:45 - 05904448 _____ (Martin Prikryl ) C:\Users\furst\Downloads\winscp576setup.exe
2015-11-12 14:45 - 2015-11-12 14:45 - 00000000 ____D C:\Program Files (x86)\WinSCP
2015-11-11 16:55 - 2015-11-07 04:19 - 00040072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2015-11-11 16:55 - 2015-11-05 18:00 - 22343800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 18487552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 18389112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 16561320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 15933912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 13533608 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 01016360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00877688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00823232 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00689784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00674096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00539648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00500872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00445216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00422568 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00414000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00369456 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00177416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00155792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2015-11-11 16:55 - 2015-11-05 18:00 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 42914096 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 37882160 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 15839200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 14844304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 12870192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 12040952 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 02876720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 02496632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 01905456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435891.dll
2015-11-11 16:54 - 2015-11-05 18:00 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435891.dll
2015-11-11 15:20 - 2015-11-11 15:20 - 00000000 ____D C:\Users\furst\Desktop\strapo-VERSUS
2015-11-11 12:33 - 2015-11-11 12:33 - 00000000 ____D C:\Program Files (x86)\FinalWire
2015-11-11 12:32 - 2015-11-11 12:32 - 16481080 _____ (FinalWire Ltd. ) C:\Users\furst\Downloads\aida64extreme550.exe
2015-11-11 11:49 - 2015-11-11 11:49 - 00010894 _____ C:\Users\furst\AppData\Local\recently-used.xbel
2015-11-11 00:10 - 2015-11-13 09:22 - 00000000 ____D C:\Call of Duty- Modern Warfare 3
2015-11-10 23:38 - 2015-11-10 23:38 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2015-11-10 19:24 - 2015-11-05 06:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-10 19:24 - 2015-11-05 06:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-10 19:24 - 2015-11-05 05:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-10 19:24 - 2015-11-05 05:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-10 19:24 - 2015-11-05 05:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-10 19:24 - 2015-11-05 05:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-10 19:24 - 2015-11-05 05:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-10 19:24 - 2015-11-05 05:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-10 19:24 - 2015-11-05 04:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-10 19:24 - 2015-11-05 04:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-10 19:24 - 2015-11-05 04:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-10 19:24 - 2015-11-05 04:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-10 19:24 - 2015-11-05 04:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-10 19:24 - 2015-11-05 04:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-10 19:24 - 2015-11-05 04:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-10 19:23 - 2015-11-05 06:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-10 19:23 - 2015-11-05 06:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-10 19:23 - 2015-11-05 06:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-10 19:23 - 2015-11-05 06:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-10 19:23 - 2015-11-05 06:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-10 19:23 - 2015-11-05 06:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-10 19:23 - 2015-11-05 05:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-10 19:23 - 2015-11-05 05:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-10 19:23 - 2015-11-05 05:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-10 19:23 - 2015-11-05 05:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-10 19:23 - 2015-11-05 05:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-10 19:23 - 2015-11-05 05:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-10 19:23 - 2015-11-05 05:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-10 19:23 - 2015-11-05 05:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-10 19:23 - 2015-11-05 05:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-10 19:23 - 2015-11-05 05:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-10 19:23 - 2015-11-05 05:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-10 19:23 - 2015-11-05 05:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-10 19:23 - 2015-11-05 05:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-10 19:23 - 2015-11-05 05:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-10 19:23 - 2015-11-05 05:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-10 19:23 - 2015-11-05 05:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-10 19:23 - 2015-11-05 05:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-10 19:23 - 2015-11-05 05:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-10 19:23 - 2015-11-05 05:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-10 19:23 - 2015-11-05 04:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-10 19:23 - 2015-11-05 04:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-10 19:23 - 2015-11-05 04:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-10 19:23 - 2015-11-05 04:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-10 19:23 - 2015-11-05 04:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-10 19:23 - 2015-11-05 04:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-10 19:23 - 2015-11-05 04:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-10 19:23 - 2015-11-05 04:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-10 19:23 - 2015-11-05 04:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-10 19:23 - 2015-11-05 04:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-10 19:23 - 2015-11-05 04:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-10 19:23 - 2015-11-05 04:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-10 19:23 - 2015-11-05 04:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-10 13:54 - 2015-11-10 23:04 - 00000000 ____D C:\Users\furst\Downloads\Call.of.Duty.Modern.Warfare.3-RELOADED
2015-11-10 13:53 - 2015-11-10 13:53 - 00071460 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_Modern_Warfare_3.torrent
2015-11-10 10:58 - 2015-11-10 10:58 - 00004985 _____ C:\Users\furst\Downloads\marcelove_zadanie.txt
2015-11-08 23:37 - 2015-11-08 23:37 - 00000000 ____D C:\Users\furst\AppData\Local\SKIDROW
2015-11-08 23:37 - 2015-11-08 23:37 - 00000000 ____D C:\Users\furst\AppData\Local\Activision
2015-11-08 23:24 - 2015-11-08 23:24 - 00000000 ____D C:\Program Files (x86)\Activision
2015-11-08 17:32 - 2015-11-08 17:32 - 00330486 _____ C:\Users\furst\Downloads\1_Algoritmus_pokracujeme.pptx
2015-11-08 17:31 - 2015-11-08 17:31 - 00708942 _____ C:\Users\furst\Downloads\5_Strukturovane_udajove_typy_polia_struktury_uniony.pptx
2015-11-08 17:31 - 2015-11-08 17:31 - 00636253 _____ C:\Users\furst\Downloads\4_Zakladne_riadiace_struktury_a_udajove_typy.pptx
2015-11-08 17:31 - 2015-11-08 17:31 - 00104163 _____ C:\Users\furst\Downloads\3_Rozhodovacie tabuľky.pptx
2015-11-08 15:21 - 2015-11-08 22:31 - 00000000 ____D C:\Users\furst\Downloads\Call of Duty - Black Ops CZ
2015-11-08 15:20 - 2015-11-08 15:20 - 00037994 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_Black_Ops_CZ.torrent
2015-11-08 15:18 - 2015-11-08 15:18 - 00105368 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_Advanced_Warfare_2014_.torrent
2015-11-08 10:38 - 2015-11-08 10:38 - 00330486 _____ C:\Users\furst\Downloads\1_Algoritmus_pokracujeme (1).pptx
2015-11-08 00:06 - 2015-11-08 00:06 - 00064475 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_6_Modern_Warfare_2_Multiplayer_crack_DLC.torrent
2015-11-08 00:02 - 2015-11-08 00:02 - 00014754 _____ C:\Users\furst\Downloads\[CzT]Call_of_Duty_4_Modern_Warfare_Multiplayer_only.torrent
2015-11-05 22:37 - 2015-11-05 22:37 - 00017396 _____ C:\Users\furst\Downloads\CSharp_Minesweeper-master.zip
2015-11-04 17:17 - 2015-11-04 17:17 - 00001004 _____ C:\Users\furst\Downloads\cvicenie2 (1)
2015-11-04 10:20 - 2015-11-04 10:20 - 00000000 ____D C:\Users\furst\AppData\Roaming\inkscape
2015-10-30 11:00 - 2015-11-12 15:48 - 00002232 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-30 02:35 - 2015-10-30 02:35 - 00001004 _____ C:\Users\furst\Downloads\cvicenie2
2015-10-29 05:34 - 2015-10-29 05:34 - 00584288 _____ (Oracle Corporation) C:\Users\furst\Downloads\JavaSetup8u65.exe
2015-10-29 05:21 - 2015-10-29 05:21 - 00000711 _____ C:\Users\furst\Downloads\marcel.txt
2015-10-29 05:19 - 2015-10-29 05:20 - 00000000 ____D C:\Users\furst\AppData\Roaming\Notepad++
2015-10-29 05:19 - 2015-10-29 05:19 - 04102262 _____ C:\Users\furst\Downloads\npp.6.8.5.Installer.exe
2015-10-29 05:19 - 2015-10-29 05:19 - 00000000 ____D C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2015-10-29 05:19 - 2015-10-29 05:19 - 00000000 ____D C:\Program Files (x86)\Notepad++
2015-10-29 05:12 - 2015-10-29 05:12 - 00000000 ____D C:\WINDOWS\OCR
2015-10-29 05:04 - 2015-11-12 15:48 - 00001047 _____ C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Voliteľné funkcie.lnk
2015-10-29 05:04 - 2015-07-09 13:39 - 04847104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-10-29 05:04 - 2015-07-09 13:36 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-10-29 05:04 - 2015-07-09 13:28 - 06358016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-10-29 05:04 - 2015-07-09 13:25 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-10-29 05:04 - 2015-07-09 13:25 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-10-29 03:41 - 2015-10-29 03:41 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudmdm.sys
2015-10-29 03:40 - 2015-10-29 03:40 - 00108800 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\WINDOWS\system32\Drivers\ssudbus.sys
2015-10-28 06:56 - 2015-10-28 09:14 - 1811108549 ____R C:\Users\furst\Downloads\Pixely 2015.mp4
2015-10-28 06:56 - 2015-10-28 08:18 - 00000000 ____D C:\Users\furst\Downloads\San.Andreas.2015.480p.BDRip.XviD.AC3.CZ-HiDE
2015-10-28 06:56 - 2015-10-28 06:56 - 00015632 _____ C:\Users\furst\Downloads\[CzT]San_Andreas_2015_CZ_.torrent
2015-10-28 06:55 - 2015-10-28 08:18 - 1531378240 ____R C:\Users\furst\Downloads\Tomorrowland.2015.BRRip.XviD.AC3-RiSiNG.avi
2015-10-28 06:55 - 2015-10-28 06:55 - 00017820 _____ C:\Users\furst\Downloads\[CzT]Pixely_Pixels_2015_CZ_WebRip_.torrent
2015-10-28 06:55 - 2015-10-28 06:55 - 00015186 _____ C:\Users\furst\Downloads\[CzT]Zeme_zitrka_Tomorrowland_2015_CZ_.torrent
2015-10-27 12:33 - 2015-10-27 12:59 - 1652660224 ____R C:\Users\furst\Downloads\Insidious.3.2015.480p.BDRip.XviD.AC3.CZ.avi
2015-10-27 12:33 - 2015-10-27 12:33 - 00016514 _____ C:\Users\furst\Downloads\[CzT]Insidious_3_Pocatek_Insidious_3_2015_CZ_.torrent
2015-10-26 06:18 - 2015-10-26 06:18 - 47330815 _____ C:\Users\furst\Downloads\asd.zip
2015-10-26 04:29 - 2015-10-26 04:29 - 00000704 _____ C:\Users\furst\Downloads\arraylists.cs
2015-10-26 04:21 - 2015-10-26 04:21 - 00000000 ____D C:\Users\furst\AppData\Roaming\NuGet
2015-10-25 06:47 - 2015-10-25 06:47 - 00000670 _____ C:\Users\furst\Downloads\A1.txt
2015-10-24 14:56 - 2015-10-24 15:09 - 886966272 ____R C:\Users\furst\Downloads\Just.Go.With.It.2011.BRRip.XviD.CZ-LEADERs.avi
2015-10-24 14:55 - 2015-10-24 14:55 - 00017488 _____ C:\Users\furst\Downloads\[CzT]Zkus_me_rozesmat_Just_Go_with_It_2011_.torrent
2015-10-24 10:05 - 2015-10-24 10:44 - 1505116160 ____R C:\Users\furst\Downloads\Můj otec je šílenec.avi
2015-10-24 10:05 - 2015-10-24 10:05 - 00015017 _____ C:\Users\furst\Downloads\[CzT]Muj_otec_je_silenec_That_s_My_Boy_2012_.torrent
2015-10-24 10:00 - 2015-10-24 10:00 - 00014420 _____ C:\Users\furst\Downloads\[CzT]Annabelle_2014_CZ_.torrent
2015-10-24 10:00 - 2015-10-24 10:00 - 00000000 ____D C:\Users\furst\Downloads\Annabelle 2014 Cz dab
2015-10-23 10:11 - 2015-10-23 10:11 - 00000017 _____ C:\Users\furst\AppData\Local\resmon.resmoncfg
2015-10-21 23:50 - 2015-10-21 23:50 - 00000000 ____D C:\Users\furst\AppData\Local\webkit
2015-10-21 01:24 - 2015-11-14 11:39 - 00000000 ____D C:\WINDOWS\system32\log
2015-10-20 11:52 - 2015-10-20 11:52 - 00000368 _____ C:\Users\furst\Downloads\kokotina-xy (1).txt
2015-10-20 11:51 - 2015-10-20 11:51 - 00000368 _____ C:\Users\furst\Downloads\kokotina-xy.txt
2015-10-19 03:32 - 2015-11-05 22:38 - 00000000 ____D C:\Users\furst\Documents\Visual Studio 2015
2015-10-19 03:29 - 2015-10-19 03:30 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-19 03:29 - 2015-10-19 03:29 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition
2015-10-19 03:28 - 2015-10-19 03:28 - 00000000 ____D C:\Program Files (x86)\ShellDir
2015-10-19 03:28 - 2015-10-19 03:28 - 00000000 ____D C:\Program Files (x86)\Microsoft ASP.NET
2015-10-19 03:26 - 2015-10-19 03:26 - 00000000 ____D C:\Program Files\Microsoft DNX
2015-10-19 03:22 - 2015-10-19 03:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Web Tools
2015-10-19 03:21 - 2015-11-14 20:00 - 00048298 _____ C:\WINDOWS\system32\perfh01B.dat
2015-10-19 03:21 - 2015-11-14 20:00 - 00017950 _____ C:\WINDOWS\system32\perfc01B.dat
2015-10-19 03:21 - 2015-10-19 03:21 - 00000000 ____D C:\Program Files\IIS Express
2015-10-19 03:21 - 2015-10-19 03:21 - 00000000 ____D C:\Program Files (x86)\IIS Express
2015-10-19 03:20 - 2015-10-19 03:20 - 00000000 ____D C:\Program Files (x86)\Microsoft Office365 Tools
2015-10-19 03:20 - 2015-10-19 03:20 - 00000000 ____D C:\Program Files (x86)\AppInsights
2015-10-19 03:17 - 2015-10-19 03:17 - 00000000 ____D C:\Program Files\IIS
2015-10-19 03:17 - 2015-10-19 03:17 - 00000000 ____D C:\Program Files (x86)\NuGet
2015-10-19 03:17 - 2015-10-19 03:17 - 00000000 ____D C:\Program Files (x86)\Microsoft WCF Data Services
2015-10-19 03:17 - 2015-10-19 03:17 - 00000000 ____D C:\Program Files (x86)\IIS
2015-10-19 03:15 - 2015-10-19 03:15 - 00000000 ____D C:\Program Files\Microsoft Visual Studio 12.0
2015-10-19 03:15 - 2015-10-19 03:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2015-10-19 03:12 - 2015-10-19 03:29 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2015-10-19 03:12 - 2015-10-19 03:12 - 00000000 ____D C:\WINDOWS\symbols
2015-10-19 03:12 - 2015-10-19 03:12 - 00000000 ____D C:\Program Files (x86)\Microsoft Help Viewer
2015-10-19 03:11 - 2015-07-09 14:53 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2015-10-19 03:11 - 2015-07-09 14:36 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2015-10-19 03:11 - 2015-07-09 13:49 - 01133056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2015-10-19 03:11 - 2015-07-09 13:49 - 00644608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2015-10-19 03:11 - 2015-07-09 13:48 - 06365696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2015-10-19 03:11 - 2015-07-09 13:40 - 01460736 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2015-10-19 03:11 - 2015-07-09 13:40 - 00875008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2015-10-19 03:11 - 2015-07-09 13:39 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2015-10-19 03:11 - 2015-07-09 13:38 - 08244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2015-10-19 03:11 - 2015-07-09 13:31 - 03597312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2015-10-19 03:11 - 2015-07-09 13:30 - 03680768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2015-10-19 03:11 - 2015-07-09 13:28 - 02439168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2015-10-19 03:11 - 2015-07-09 13:28 - 00916480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2015-10-19 03:11 - 2015-07-09 13:28 - 00761856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2015-10-19 03:11 - 2015-07-09 13:28 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2015-10-19 03:11 - 2015-07-09 13:28 - 00308224 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2015-10-19 03:11 - 2015-07-09 13:27 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2015-10-19 03:11 - 2015-07-09 13:26 - 00346624 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2015-10-19 03:11 - 2015-07-09 13:24 - 00233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2015-10-19 03:11 - 2015-07-09 13:21 - 04656128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2015-10-19 03:11 - 2015-07-09 13:20 - 04751872 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2015-10-19 03:11 - 2015-07-09 13:18 - 03257856 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2015-10-19 03:11 - 2015-07-09 13:18 - 01069568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2015-10-19 03:11 - 2015-07-09 13:18 - 00877568 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2015-10-19 03:11 - 2015-07-09 13:17 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2015-10-19 03:11 - 2015-07-09 13:17 - 00413184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2015-10-19 03:11 - 2015-07-09 13:17 - 00173056 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2015-10-19 03:11 - 2015-07-09 13:17 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2015-10-19 03:11 - 2015-07-09 13:17 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2015-10-19 03:11 - 2015-07-09 13:17 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2015-10-19 03:11 - 2015-07-09 13:16 - 00366592 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2015-10-19 03:11 - 2015-07-09 13:16 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2015-10-19 03:11 - 2015-07-09 13:16 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2015-10-19 03:11 - 2015-07-09 13:13 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2015-10-19 03:10 - 2015-10-19 03:30 - 00000000 ____D C:\Program Files\Microsoft SQL Server
2015-10-19 03:10 - 2015-10-19 03:30 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server
2015-10-19 03:10 - 2015-10-19 03:14 - 00000000 ____D C:\WINDOWS\SysWOW64\1033
2015-10-19 03:08 - 2015-10-19 03:11 - 00000000 ____D C:\WINDOWS\system32\1033
2015-10-19 03:07 - 2015-10-19 03:31 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2015-10-19 03:07 - 2015-10-19 03:29 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 14.0
2015-10-19 03:07 - 2015-10-19 03:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsSimulatorDriver_01_11_00.Wdf
2015-10-19 00:15 - 2015-10-19 00:15 - 00161718 _____ C:\Users\furst\Downloads\2_Znacky pre zapis algoritmov (2).pptx
2015-10-17 06:14 - 2015-10-17 06:14 - 00000000 ____D C:\Users\furst\Documents\My Games

Marcelko69
nováček
Příspěvky: 11
Registrován: listopad 15
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu

Příspěvekod Marcelko69 » 15 lis 2015 00:09

FRST pokračovanie log:

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-11-15 00:02 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\system32\sru
2015-11-14 23:44 - 2015-10-02 09:33 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-11-14 23:21 - 2015-09-07 01:38 - 00000000 ____D C:\Users\furst\AppData\Roaming\TS3Client
2015-11-14 23:05 - 2015-09-16 07:52 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-11-14 21:31 - 2015-09-10 23:55 - 00000000 ____D C:\Users\furst\AppData\Roaming\Skype
2015-11-14 21:31 - 2015-09-06 16:19 - 00000000 ____D C:\Program Files (x86)\Steam
2015-11-14 20:30 - 2015-09-23 08:15 - 00000000 ____D C:\Users\furst\Documents\BloodBowl2
2015-11-14 20:00 - 2015-09-07 00:56 - 00974714 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-11-14 19:58 - 2015-09-06 16:09 - 00000000 ____D C:\Users\furst\AppData\Local\VirtualStore
2015-11-14 19:57 - 2015-10-02 09:33 - 00000972 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-11-14 19:57 - 2015-09-08 07:25 - 00000000 ____D C:\Users\furst\AppData\Roaming\uTorrent
2015-11-14 19:57 - 2015-09-07 00:45 - 00000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-14 19:56 - 2015-09-07 02:37 - 00431518 _____ C:\WINDOWS\PFRO.log
2015-11-14 19:56 - 2015-09-07 00:51 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-11-14 19:56 - 2015-09-07 00:46 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-11-14 19:55 - 2015-09-06 16:14 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-14 17:20 - 2015-09-07 07:24 - 00004210 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D9F98A37-96DA-4FC2-A8EC-BAEFC7BF8042}
2015-11-14 14:04 - 2015-09-06 16:20 - 00000000 ____D C:\Users\furst\Desktop\foto
2015-11-14 11:39 - 2015-09-06 16:06 - 00000000 ____D C:\Users\furst
2015-11-14 09:03 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-11-12 16:56 - 2015-10-02 08:53 - 00000000 ____D C:\Program Files\Common Files\mm1zcbfg
2015-11-12 15:48 - 2015-10-12 05:24 - 00001149 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
2015-11-12 15:48 - 2015-10-11 10:03 - 00001025 _____ C:\Users\furst\Desktop\Dev-C++.lnk
2015-11-12 15:48 - 2015-10-06 23:24 - 00000964 _____ C:\Users\Public\Desktop\Inkscape 0.91.lnk
2015-11-12 15:48 - 2015-10-06 22:51 - 00000988 _____ C:\Users\furst\Desktop\XnView.lnk
2015-11-12 15:48 - 2015-10-06 22:48 - 00000971 _____ C:\Users\furst\Desktop\GIMP 2.lnk
2015-11-12 15:48 - 2015-09-16 07:50 - 00001105 _____ C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2015-11-12 15:48 - 2015-09-07 01:38 - 00001280 _____ C:\Users\furst\Desktop\TeamSpeak 3 Client.lnk
2015-11-12 15:48 - 2015-09-06 16:19 - 00001032 _____ C:\Users\Public\Desktop\Steam.lnk
2015-11-12 15:48 - 2015-09-06 16:14 - 00000440 _____ C:\Users\furst\Desktop\Tento počítač - odkaz.lnk
2015-11-12 15:48 - 2015-09-06 16:13 - 00002338 _____ C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-12 15:03 - 2015-10-02 11:02 - 00290304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\subinacl.exe
2015-11-11 16:31 - 2015-09-16 07:35 - 00000000 ____D C:\Users\furst\AppData\Roaming\Tunngle
2015-11-11 16:24 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-11-11 15:20 - 2015-09-06 16:17 - 00000000 ____D C:\Users\furst\Desktop\škola
2015-11-11 14:03 - 2015-09-07 00:40 - 00029777 _____ C:\WINDOWS\setupact.log
2015-11-11 14:00 - 2015-09-16 00:36 - 00000000 ____D C:\Users\furst\Desktop\Games
2015-11-11 14:00 - 2015-09-06 16:22 - 00000000 ____D C:\Users\furst\Desktop\ja a láska
2015-11-11 12:21 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\SysWOW64\sk-SK
2015-11-11 12:21 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\system32\sk-SK
2015-11-11 12:21 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-11 11:41 - 2015-10-06 22:49 - 00000000 ____D C:\Users\furst\.gimp-2.8
2015-11-11 03:05 - 2015-09-16 07:52 - 00003816 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-11-10 20:26 - 2015-09-06 16:19 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-11-10 20:24 - 2015-09-07 01:36 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-11-10 20:19 - 2015-09-07 01:36 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-10 11:09 - 2015-09-06 16:06 - 00000000 ___RD C:\Users\furst\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-11-09 23:35 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\rescache
2015-11-09 17:39 - 2015-10-12 05:24 - 00000000 ____D C:\Users\furst\.VirtualBox
2015-11-08 23:35 - 2015-09-19 21:08 - 00000000 ____D C:\WINDOWS\SysWOW64\directx
2015-11-07 04:19 - 2015-07-23 03:02 - 11227280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-11-05 18:00 - 2015-07-23 03:02 - 03540360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-11-05 18:00 - 2015-07-23 03:02 - 03126800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-11-05 18:00 - 2015-07-23 03:02 - 00034493 _____ C:\WINDOWS\system32\nvinfo.pb
2015-11-05 16:08 - 2015-09-08 02:53 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-11-05 16:08 - 2015-09-08 02:53 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 00114480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 00074872 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-11-05 16:08 - 2015-09-08 02:53 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-11-03 19:20 - 2015-09-06 16:27 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-03 19:20 - 2015-09-06 16:27 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-02 18:31 - 2015-09-06 16:25 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-11-02 17:57 - 2015-09-06 16:25 - 00000000 ____D C:\Program Files\Windows Defender
2015-11-02 17:55 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\SystemResources
2015-11-02 17:55 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-11-02 17:55 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\Globalization
2015-11-02 17:55 - 2015-09-06 16:14 - 00000000 ____D C:\WINDOWS\servicing
2015-11-02 17:45 - 2015-09-06 16:25 - 00000000 ____D C:\WINDOWS\registration
2015-11-01 03:00 - 2015-09-06 16:13 - 00000000 ___RD C:\Users\furst\OneDrive
2015-10-30 11:00 - 2015-09-06 16:13 - 00000000 ____D C:\Users\furst\AppData\Local\Google
2015-10-29 05:35 - 2015-09-07 07:23 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-10-29 05:35 - 2015-09-07 07:23 - 00000000 ____D C:\Users\furst\.oracle_jre_usage
2015-10-29 05:35 - 2015-09-07 07:23 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-29 04:52 - 2015-09-06 16:13 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-28 14:49 - 2015-09-08 02:53 - 06027430 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-10-26 10:47 - 2015-10-13 23:39 - 00000000 ____D C:\Users\furst\AppData\Local\gtk-2.0
2015-10-19 03:13 - 2015-09-06 16:31 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-10-19 03:08 - 2015-09-06 16:25 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-18 11:22 - 2015-09-06 16:25 - 00000000 ____D C:\Users\furst\Desktop\Filmy

==================== Files in the root of some directories =======

2015-10-02 09:12 - 2015-10-02 09:13 - 4875861 _____ () C:\Program Files\Common Files\hxvl5wjw.exe
2015-11-12 15:15 - 2015-11-12 23:19 - 0000600 _____ () C:\Users\furst\AppData\Roaming\winscp.rnd
2015-11-11 11:49 - 2015-11-11 11:49 - 0010894 _____ () C:\Users\furst\AppData\Local\recently-used.xbel
2015-10-23 10:11 - 2015-10-23 10:11 - 0000017 _____ () C:\Users\furst\AppData\Local\resmon.resmoncfg
2015-09-07 00:46 - 2015-09-07 00:46 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-11-10 13:23

==================== End of FRST.txt ============================


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Seznam[Bot] a 95 hostů