Vysoka zatěž ram ,zasekáváni prohlížeču Vyřešeno
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
farbar se seknul
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-11-2014
Ran by xxx (administrator) on XXX-PC on 22-11-2014 12:16:33
Running from C:\Users\xxx\Downloads
Loaded Profile: xxx (Available profiles: xxx)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {15b2313e-5558-11e1-a333-001b388cbe5c} - E:\AutoRun.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8ab7-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8aba-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {e080bcab-c91d-11e1-9360-001b388cbe5c} - E:\application\Nokia_Internet_Modem.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {6b43620d-50f4-4094-aea5-bd840890f757} URL = http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {7904d8f0-7208-4462-95d8-b4887ed9d3a5} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {ea8f2e38-3cb0-42a5-ad58-0c729227f856} URL = http://www.firmy.cz/phr/{searchTerms}?sourceid=IEListicka_12
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\..\Interfaces\{AEB3D5D8-CE48-424E-AF3F-D04C86A5B07F}: [NameServer] 208.67.222.222,208.67.220.220
FireFox:
========
FF ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\4ejcuupx.default-1414919215950
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: CENZURA - Media Downloader - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\4ejcuupx.default-1414919215950\Extensions\paulsaintuzb@gmail.com.xpi [2014-11-18]
Chrome:
=======
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 DrvAgent32; C:\Windows\system32\Drivers\DrvAgent32.sys [23456 2014-11-04] (Phoenix Technologies) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-11-14] (Disc Soft Ltd)
R3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [159232 2007-02-22] (Conexant Systems Inc.)
S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 PAC7302; system32\DRIVERS\PAC7302.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-22 08:35 - 2014-11-22 08:37 - 00011752 ____C () C:\Users\xxx\Downloads\Addition.txt
2014-11-22 08:34 - 2014-11-22 12:16 - 00005961 ____C () C:\Users\xxx\Downloads\FRST.txt
2014-11-22 08:33 - 2014-11-22 12:16 - 00000000 ___DC () C:\FRST
2014-11-22 08:32 - 2014-11-22 08:32 - 00000355 ____C () C:\Start_.cmd
2014-11-22 08:31 - 2014-11-22 08:32 - 00000000 __SDC () C:\32788R22FWJFW
2014-11-22 08:30 - 2014-11-22 08:30 - 01108992 ____C (Farbar) C:\Users\xxx\Downloads\FRST.exe
2014-11-22 04:56 - 2014-11-22 05:09 - 232003996 ____C () C:\Users\xxx\Downloads\Cum-eating-cuckold-fantasies-1.mp4
2014-11-22 01:45 - 2014-11-22 01:45 - 00025785 ____C () C:\ComboFix.txt
2014-11-20 22:46 - 2014-11-20 23:51 - 1183434752 ____C () C:\Users\xxx\Downloads\Noe (Noah - 2014) novinka, dobrodružný, katastrofický, biblický, akční, cz dabing.avi
2014-11-20 21:58 - 2014-11-20 22:00 - 529977244 ____C () C:\Users\xxx\Downloads\Noe Noah 2014 Cz dabing.avi
2014-11-20 18:17 - 2014-11-20 18:17 - 00000000 ___DC () C:\Users\xxx\Downloads\Originals
2014-11-20 18:16 - 2014-11-20 18:16 - 00088064 ___HC () C:\Users\xxx\Downloads\photothumb.db
2014-11-20 18:15 - 2014-11-20 18:15 - 00058016 ____C () C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-20 12:40 - 2011-06-26 07:45 - 00256000 ____C () C:\Windows\PEV.exe
2014-11-20 12:40 - 2010-11-07 18:20 - 00208896 ____C () C:\Windows\MBR.exe
2014-11-20 12:40 - 2009-04-20 05:56 - 00060416 ____C (NirSoft) C:\Windows\NIRCMD.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00518144 ____C (SteelWerX) C:\Windows\SWREG.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00406528 ____C (SteelWerX) C:\Windows\SWSC.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00098816 ____C () C:\Windows\sed.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00080412 ____C () C:\Windows\grep.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00068096 ____C () C:\Windows\zip.exe
2014-11-20 12:39 - 2014-11-22 02:09 - 00000000 ___DC () C:\Windows\erdnt
2014-11-20 12:39 - 2014-11-22 01:45 - 00000000 ___DC () C:\Qoobox
2014-11-20 12:38 - 2014-11-20 12:38 - 05598306 ___RC (Swearware) C:\Users\xxx\Desktop\ComboFix.exe
2014-11-19 19:27 - 2014-11-19 19:27 - 00013312 ___HC () C:\Users\xxx\Desktop\photothumb.db
2014-11-19 18:20 - 2014-11-19 19:26 - 1191654528 ____C () C:\Users\xxx\Downloads\STRÁŽCI GALAXIE 2014 CZ titulky BLURAY.avi
2014-11-18 19:52 - 2014-11-18 19:57 - 17372042 ____C () C:\Users\xxx\Downloads\Timmy Time S03E06 Baby Time Timmy (Mobile).3gp
2014-11-18 19:51 - 2014-11-18 19:53 - 06218877 ____C () C:\Users\xxx\Downloads\Timmy Time S03E12 Fireman Timmy (Mobile).3gp
2014-11-17 20:57 - 2014-11-17 21:54 - 1025509792 ____C () C:\Users\xxx\Downloads\V-zajetí-démonů-2013-DVDRip-CZ-Dabing.avi
2014-11-17 20:43 - 2014-11-17 20:43 - 00000386 ____C () C:\Users\xxx\Desktop\Vyměnitelný disk (F) – zástupce.lnk
2014-11-16 22:42 - 2014-11-16 22:20 - 00024064 ____C () C:\Windows\zoek-delete.exe
2014-11-16 22:21 - 2014-11-01 12:41 - 00008835 ____C () C:\zoek-results2014-11-01-114145.log
2014-11-16 22:19 - 2014-11-16 22:19 - 01294848 ____C () C:\Users\xxx\Downloads\zoek.exe
2014-11-16 16:46 - 2014-11-16 16:48 - 10056251 ____C () C:\Users\xxx\Desktop\Zábavné video o opiciach.3gp
2014-11-16 13:25 - 2014-11-16 13:25 - 01707532 ____C (Thisisu) C:\Users\xxx\Downloads\JRT.exe
2014-11-16 10:23 - 2014-11-16 10:24 - 14678104 ____C () C:\Users\xxx\Downloads\RogueKiller.exe
2014-11-16 10:03 - 2014-11-16 22:49 - 00001942 ____C () C:\Windows\PFRO.log
2014-11-15 20:16 - 2014-11-16 10:19 - 00114904 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-15 20:15 - 2014-11-15 20:15 - 00001020 ____C () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-15 20:15 - 2014-11-15 20:15 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-15 20:15 - 2014-11-15 20:15 - 00000000 ___DC () C:\Program Files\Malwarebytes Anti-Malware
2014-11-15 20:15 - 2014-10-01 11:11 - 00075480 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-15 20:15 - 2014-10-01 11:11 - 00051928 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-15 20:15 - 2014-10-01 11:11 - 00023256 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-15 20:14 - 2014-11-15 20:14 - 19828376 ____C (Malwarebytes Corporation ) C:\Users\xxx\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-15 20:08 - 2014-11-15 20:08 - 02140160 ____C () C:\Users\xxx\Downloads\adwcleaner_4.101.exe
2014-11-15 19:57 - 2014-11-15 19:57 - 00448512 ____C (OldTimer Tools) C:\Users\xxx\Downloads\TFC(1).exe
2014-11-15 18:51 - 2014-11-15 18:51 - 00003106 ____C () C:\Users\xxx\Downloads\hijackthis.log
2014-11-15 18:48 - 2014-11-15 18:48 - 00388608 ____C (Trend Micro Inc.) C:\Users\xxx\Downloads\HijackThis.exe
2014-11-15 18:07 - 2014-11-15 18:07 - 00000000 ___DC () C:\ProgramData\Emsisoft
2014-11-15 17:58 - 2014-11-16 22:49 - 00000000 ___DC () C:\Program Files\Emsisoft Anti-Malware
2014-11-15 17:46 - 2014-11-15 18:16 - 00001340 ____C () C:\Windows\system32\.crusader
2014-11-15 17:36 - 2014-11-15 17:47 - 00000000 ___DC () C:\ProgramData\HitmanPro
2014-11-15 17:35 - 2014-11-15 17:36 - 10284408 ____C (SurfRight B.V.) C:\Users\xxx\Downloads\HitmanPro.exe
2014-11-15 17:21 - 2014-11-15 17:21 - 00267432 ____C () C:\Windows\system32\FNTCACHE.DAT
2014-11-15 17:06 - 2014-11-22 12:10 - 00057686 ____C () C:\Windows\setupact.log
2014-11-15 17:06 - 2014-11-15 17:06 - 00000000 ____C () C:\Windows\setuperr.log
2014-11-15 03:32 - 2014-11-15 03:32 - 00407040 ____C () C:\Users\xxx\Downloads\WebcamSchnappschuss.exe
2014-11-15 02:33 - 2014-11-15 02:33 - 00001211 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2014-11-15 02:33 - 2014-11-15 02:33 - 00000000 ___DC () C:\Windows\cs
2014-11-15 02:32 - 2014-11-15 02:32 - 00001280 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2014-11-15 02:31 - 2014-11-15 02:32 - 00000020 ____C () C:\Windows\řőŠ
2014-11-15 02:31 - 2014-11-15 02:31 - 00000000 ___DC () C:\Program Files\Microsoft SQL Server Compact Edition
2014-11-15 02:30 - 2014-11-15 02:30 - 00000000 ___DC () C:\Windows\PCHEALTH
2014-11-15 02:29 - 2014-11-15 02:31 - 00000000 ___DC () C:\Program Files\Windows Live
2014-11-15 02:26 - 2010-06-02 04:55 - 00527192 ____C (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-11-15 02:26 - 2010-06-02 04:55 - 00074072 ____C (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-11-15 02:26 - 2010-05-26 11:41 - 02106216 ____C (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-11-15 02:26 - 2010-05-26 11:41 - 00248672 ____C (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-11-15 02:24 - 2009-09-04 17:29 - 00453456 ____C (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-11-15 02:23 - 2006-11-29 13:06 - 03426072 ____C (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-11-15 02:21 - 2014-11-22 04:27 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Windows Live
2014-11-15 02:21 - 2014-11-15 02:21 - 00000000 ___DC () C:\Program Files\Common Files\Windows Live
2014-11-15 02:20 - 2014-11-15 02:20 - 01243336 ____C (společnost Microsoft Corporation) C:\Users\xxx\Downloads\wlsetup-web.exe
2014-11-15 01:59 - 2014-11-03 10:04 - 00043688 ____C (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2014-11-15 01:56 - 2014-11-15 01:56 - 00728960 ____C (Enigma Software Group USA, LLC.) C:\Users\xxx\Downloads\SpyHunter-installer.exe
2014-11-14 18:45 - 2014-11-14 18:46 - 00037875 ____C () C:\Users\xxx\Downloads\stahování.htm
2014-11-14 01:12 - 2014-11-15 10:07 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\dvdcss
2014-11-14 01:08 - 2014-11-14 01:08 - 00001856 ____C () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2014-11-14 01:08 - 2014-11-14 01:08 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-11-14 01:04 - 2014-11-15 10:28 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\DAEMON Tools Lite
2014-11-14 01:04 - 2014-11-14 01:04 - 00243128 ____C (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-11-14 01:04 - 2014-11-14 01:04 - 00000000 ___DC () C:\Program Files\DAEMON Tools Lite
2014-11-14 01:03 - 2014-11-14 01:11 - 00000000 ___DC () C:\ProgramData\DAEMON Tools Lite
2014-11-14 00:59 - 2014-11-14 00:59 - 12891208 ____C (Ashampoo GmbH & Co. KG ) C:\Users\xxx\Downloads\ashampoo_burning_studio_6_free_6.84_13471.exe
2014-11-14 00:53 - 2014-11-14 00:53 - 07716056 ____C (Alcohol Soft Development Team) C:\Users\xxx\Downloads\Alcohol120_trial_2.0.3.6839.exe
2014-11-13 21:15 - 2014-11-14 00:44 - 3737485468 ____C () C:\Users\xxx\Downloads\Bee-Gees---One-Night-Only-live-DVD-(1997).nrg
2014-11-10 15:00 - 2014-11-10 15:01 - 00000000 ___DC () C:\ks
2014-11-09 11:06 - 2014-11-09 11:06 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kid Key Lock
2014-11-09 11:06 - 2014-11-09 11:06 - 00000000 ___DC () C:\Program Files\100dof_kidkeylock
2014-11-07 13:22 - 2014-11-07 13:22 - 10156325 ____C () C:\Users\xxx\Downloads\N.E.R.D. _ Hypnotize U.flv
2014-11-07 13:21 - 2014-11-07 13:21 - 10156325 ____C () C:\Users\xxx\Downloads\Youngblood Hawke _ We Come Running (1).flv
2014-11-07 12:57 - 2014-11-07 13:25 - 00000000 ___DC () C:\FFOutput
2014-11-07 12:56 - 2014-11-07 12:56 - 00001116 ____C () C:\Users\xxx\Desktop\Format Factory.lnk
2014-11-07 12:56 - 2014-11-07 12:56 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-11-07 12:50 - 2014-11-07 12:50 - 00000000 ___DC () C:\Program Files\FreeTime
2014-11-06 21:13 - 2014-11-06 22:18 - 1159985152 ____C () C:\Users\xxx\Downloads\Koleje osudu 2013 CZ dabing.avi
2014-11-06 18:49 - 2014-11-06 19:37 - 870252544 ____C () C:\Users\xxx\Downloads\Volani---The-Calling-2014-cz.avi
2014-11-06 18:43 - 2014-11-06 19:36 - 964947968 ____C () C:\Users\xxx\Downloads\SOUSEDI 2014 CZ dabing.avi
2014-11-06 13:20 - 2014-11-06 13:20 - 00014424 ____C () C:\Windows\system32\results.xml
2014-11-05 09:30 - 2014-11-06 13:37 - 00000512 ____C () C:\PhysicalMBR.bin
2014-11-05 01:59 - 2014-11-05 02:01 - 27410773 ____C () C:\Users\xxx\Downloads\Sex-s-naprosto-opilou-a-nadrženou-kámoškou-na-párty.mp4
2014-11-05 00:40 - 2014-11-05 00:40 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Tonium
2014-11-05 00:35 - 2014-11-05 00:35 - 00000000 ___DC () C:\Users\xxx\Downloads\PME-Win-2.0.2.14170
2014-11-05 00:30 - 2014-11-05 00:31 - 33973728 ____C () C:\Users\xxx\Downloads\PME-Win-2.0.2.14170.zip
2014-11-04 23:50 - 2014-11-04 23:50 - 00000000 ___DC () C:\Program Files\trend micro
2014-11-04 23:22 - 2014-11-04 23:36 - 00000000 ___DC () C:\Program Files\Pointstone
2014-11-04 23:17 - 2014-11-04 23:17 - 02046216 ____C (Pointstone Software, LLC) C:\Users\xxx\Downloads\MemOptimizerSetup.exe
2014-11-04 22:31 - 2014-11-04 22:31 - 00000000 ___DC () C:\Program Files\CONEXANT
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\Windows\system32\Lang
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\ProgramData\IntelDLM
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\Intel
2014-11-04 22:20 - 2009-10-02 14:34 - 08198680 ____C (Intel(R) Corporation) C:\Windows\system32\TVWSetup.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00672792 ____C (Intel Corporation) C:\Windows\system32\igfxcfg.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00252952 ____C (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00173592 ____C (Intel Corporation) C:\Windows\system32\hkcmd.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00173080 ____C (Intel Corporation) C:\Windows\system32\igfxext.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00150552 ____C (Intel Corporation) C:\Windows\system32\igfxpers.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00141848 ____C (Intel Corporation) C:\Windows\system32\igfxtray.exe
2014-11-04 22:16 - 2014-11-04 22:16 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Intel
2014-11-04 22:11 - 2014-11-04 22:11 - 00019456 ____C () C:\Users\xxx\Downloads\launcher32.dll
2014-11-04 22:04 - 2014-11-04 22:04 - 00023456 ____C (Phoenix Technologies) C:\Windows\system32\Drivers\DrvAgent32.sys
2014-11-04 20:43 - 2014-11-04 20:43 - 00000000 ___DC () C:\Users\xxx\Downloads\MemTest
2014-11-03 15:36 - 2014-11-05 01:18 - 00000269 ____C () C:\Users\xxx\Documents\hizs.txt
2014-11-03 13:49 - 2014-11-03 14:51 - 1134336000 ____C () C:\Users\xxx\Downloads\Godzilla 2014 CZ dabing.avi
2014-11-03 13:19 - 2014-11-03 13:19 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Adobe
2014-11-03 11:58 - 2014-11-03 12:24 - 1303578624 ____C () C:\Users\xxx\Downloads\Need for Speed 2014 CZ dabing.avi
2014-11-01 10:26 - 2014-11-21 16:53 - 00000000 ___DC () C:\Users\xxx\AppData\Local\CrashDumps
2014-11-01 10:25 - 2014-11-16 22:49 - 00007828 ____C () C:\zoek-results.log
2014-11-01 10:22 - 2014-11-16 22:37 - 00000000 ___DC () C:\zoek_backup
2014-10-31 13:44 - 2014-11-16 20:27 - 00034808 ____C () C:\Windows\system32\Drivers\TrueSight.sys
2014-10-31 13:44 - 2014-10-31 13:44 - 00000000 ___DC () C:\ProgramData\RogueKiller
2014-10-31 13:22 - 2014-10-31 13:22 - 00000000 ___DC () C:\Windows\ERUNT
2014-10-30 14:02 - 2014-10-30 14:02 - 00001053 ____C () C:\Users\Public\Desktop\Opera.lnk
2014-10-30 14:02 - 2014-10-30 14:02 - 00001053 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-10-30 13:23 - 2014-10-30 13:23 - 00000049 ____C () C:\loi.txt
2014-10-30 11:48 - 2014-10-30 11:48 - 00000000 ___DC () C:\ProgramData\Malwarebytes
2014-10-30 11:42 - 2010-08-30 08:34 - 00536576 ____C (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-10-30 11:41 - 2014-11-16 10:13 - 00000000 ___DC () C:\AdwCleaner
2014-10-30 11:21 - 2014-10-30 11:21 - 19828376 ____C (Malwarebytes Corporation ) C:\Users\xxx\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-30 11:18 - 2014-10-30 11:18 - 00448512 ____C (OldTimer Tools) C:\Users\xxx\Downloads\TFC.exe
2014-10-30 10:09 - 2014-11-22 02:09 - 00000000 ___DC () C:\Program Files\Mozilla Firefox
2014-10-29 19:16 - 2014-11-20 21:55 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\PhotoScape
2014-10-29 19:15 - 2014-10-29 19:16 - 00000000 ___DC () C:\Program Files\PhotoScape
2014-10-29 19:15 - 2014-10-29 19:15 - 00000949 ____C () C:\Users\xxx\Desktop\PhotoScape.lnk
2014-10-29 19:15 - 2014-10-29 19:15 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-10-28 09:16 - 2014-10-30 14:03 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Opera Software
2014-10-28 09:16 - 2014-10-30 14:03 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Opera Software
2014-10-28 08:53 - 2014-10-28 08:53 - 00000000 ___DC () C:\Windows\pss
2014-10-28 02:21 - 2014-10-28 02:21 - 00701104 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-10-28 02:21 - 2014-10-28 02:21 - 00071344 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-10-28 01:44 - 2014-11-22 05:12 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\vlc
2014-10-28 01:43 - 2014-10-28 01:43 - 00000984 ____C () C:\Users\Public\Desktop\VLC media player.lnk
2014-10-28 01:43 - 2014-10-28 01:43 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-28 01:42 - 2014-10-28 01:42 - 00000000 ___DC () C:\Program Files\VideoLAN
2014-10-26 19:06 - 2014-10-27 19:00 - 00002441 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-10-26 19:06 - 2014-10-26 19:06 - 00001949 ____C () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-10-26 19:05 - 2014-10-27 18:57 - 00000000 ___DC () C:\ProgramData\Adobe
2014-10-26 19:05 - 2014-10-26 19:06 - 00000000 ___DC () C:\Program Files\Common Files\Adobe
2014-10-26 19:05 - 2014-10-26 19:05 - 00000000 ___DC () C:\Program Files\Adobe
2014-10-25 20:33 - 2014-10-25 20:33 - 00000925 ____C () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-25 20:33 - 2014-10-25 20:33 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-10-25 20:33 - 2014-10-25 20:33 - 00000000 ___DC () C:\Program Files\CCleaner
2014-10-25 19:37 - 2014-10-25 19:37 - 00007597 ____C () C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
2014-10-25 18:59 - 2014-10-25 18:59 - 00000000 _SHDC () C:\Users\xxx\AppData\Local\EmieUserList
2014-10-25 18:59 - 2014-10-25 18:59 - 00000000 _SHDC () C:\Users\xxx\AppData\Local\EmieSiteList
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-22 11:06 - 2010-11-20 22:01 - 01583226 ____C () C:\Windows\system32\PerfStringBackup.INI
2014-11-22 11:03 - 2012-02-05 02:24 - 01852864 ____C () C:\Windows\WindowsUpdate.log
2014-11-22 10:19 - 2012-04-01 11:01 - 00000000 ___DC () C:\Program Files\Opera
2014-11-22 10:19 - 2009-07-14 05:34 - 00026576 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-22 10:19 - 2009-07-14 05:34 - 00026576 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-22 10:11 - 2009-07-14 05:53 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT
2014-11-22 10:00 - 2012-06-25 17:17 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Skype
2014-11-22 02:10 - 2012-02-05 02:30 - 00000000 __RDC () C:\Users\xxx
2014-11-22 02:10 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\wfp
2014-11-22 02:09 - 2012-08-22 15:38 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Facebook
2014-11-22 02:09 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\NDF
2014-11-22 02:09 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\registration
2014-11-16 22:39 - 2012-02-12 11:02 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Google
2014-11-15 02:30 - 2009-07-14 03:37 - 00000000 ___DC () C:\Program Files\Common Files\microsoft shared
2014-11-15 02:08 - 2012-06-25 17:15 - 00000000 __RDC () C:\Program Files\Skype
2014-11-10 15:14 - 2012-02-12 16:00 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DSPlayer v0.889 lite
2014-11-09 14:55 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\Cursors
2014-11-09 14:21 - 2009-07-14 03:04 - 00000505 ____C () C:\Windows\win.ini
2014-11-04 22:09 - 2013-08-29 14:22 - 00000000 ___DC () C:\Program Files\rc
2014-11-04 22:09 - 2012-02-12 17:24 - 00000000 ___DC () C:\Games
2014-11-04 22:09 - 2009-07-14 05:52 - 00000000 __RDC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-11-04 20:32 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\LogFiles
2014-11-04 14:30 - 2012-02-12 10:21 - 00229000 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-03 19:27 - 2012-08-22 15:38 - 00000920 ____C () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job
2014-11-03 19:27 - 2012-08-22 15:38 - 00000898 ____C () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job
2014-11-03 15:12 - 2012-06-26 18:13 - 00006656 ____C () C:\Users\xxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-30 11:39 - 2012-07-13 13:27 - 00001007 ____C () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-29 12:43 - 2012-09-27 17:23 - 00000000 ___DC () C:\Webcam eye 312
2014-10-28 01:38 - 2012-10-05 08:45 - 00000000 ___DC () C:\Program Files\GRETECH
2014-10-26 19:09 - 2012-02-12 10:16 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Adobe
2014-10-25 21:17 - 2012-02-12 10:59 - 00000000 ___DC () C:\ProgramData\AVAST Software
2014-10-25 20:49 - 2012-11-22 13:16 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Unity
2014-10-25 20:35 - 2012-02-05 02:18 - 00000000 ___DC () C:\Windows\Panther
2014-10-25 20:18 - 2012-02-05 02:37 - 00000000 __HDC () C:\Program Files\InstallShield Installation Information
2014-10-25 19:07 - 2012-02-12 11:02 - 00000000 ___DC () C:\Program Files\Google
2014-10-25 19:02 - 2012-03-19 11:39 - 00000000 ___DC () C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\xxx\AppData\Local\temp\HitmanPro.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-15 05:18
==================== End Of Log ============================
Ran by xxx (administrator) on XXX-PC on 22-11-2014 12:16:33
Running from C:\Users\xxx\Downloads
Loaded Profile: xxx (Available profiles: xxx)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_189.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {15b2313e-5558-11e1-a333-001b388cbe5c} - E:\AutoRun.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8ab7-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8aba-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {e080bcab-c91d-11e1-9360-001b388cbe5c} - E:\application\Nokia_Internet_Modem.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {6b43620d-50f4-4094-aea5-bd840890f757} URL = http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {7904d8f0-7208-4462-95d8-b4887ed9d3a5} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {ea8f2e38-3cb0-42a5-ad58-0c729227f856} URL = http://www.firmy.cz/phr/{searchTerms}?sourceid=IEListicka_12
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
Tcpip\..\Interfaces\{AEB3D5D8-CE48-424E-AF3F-D04C86A5B07F}: [NameServer] 208.67.222.222,208.67.220.220
FireFox:
========
FF ProfilePath: C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\4ejcuupx.default-1414919215950
FF NewTab: hxxp://www.google.com/
FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q=
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: CENZURA - Media Downloader - C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\4ejcuupx.default-1414919215950\Extensions\paulsaintuzb@gmail.com.xpi [2014-11-18]
Chrome:
=======
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 DrvAgent32; C:\Windows\system32\Drivers\DrvAgent32.sys [23456 2014-11-04] (Phoenix Technologies) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-11-14] (Disc Soft Ltd)
R3 HdAudAddService; C:\Windows\System32\drivers\CHDART.sys [159232 2007-02-22] (Conexant Systems Inc.)
S3 cleanhlp; \??\C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [X]
S3 Huawei; system32\DRIVERS\ewdcsc.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 PAC7302; system32\DRIVERS\PAC7302.SYS [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-22 08:35 - 2014-11-22 08:37 - 00011752 ____C () C:\Users\xxx\Downloads\Addition.txt
2014-11-22 08:34 - 2014-11-22 12:16 - 00005961 ____C () C:\Users\xxx\Downloads\FRST.txt
2014-11-22 08:33 - 2014-11-22 12:16 - 00000000 ___DC () C:\FRST
2014-11-22 08:32 - 2014-11-22 08:32 - 00000355 ____C () C:\Start_.cmd
2014-11-22 08:31 - 2014-11-22 08:32 - 00000000 __SDC () C:\32788R22FWJFW
2014-11-22 08:30 - 2014-11-22 08:30 - 01108992 ____C (Farbar) C:\Users\xxx\Downloads\FRST.exe
2014-11-22 04:56 - 2014-11-22 05:09 - 232003996 ____C () C:\Users\xxx\Downloads\Cum-eating-cuckold-fantasies-1.mp4
2014-11-22 01:45 - 2014-11-22 01:45 - 00025785 ____C () C:\ComboFix.txt
2014-11-20 22:46 - 2014-11-20 23:51 - 1183434752 ____C () C:\Users\xxx\Downloads\Noe (Noah - 2014) novinka, dobrodružný, katastrofický, biblický, akční, cz dabing.avi
2014-11-20 21:58 - 2014-11-20 22:00 - 529977244 ____C () C:\Users\xxx\Downloads\Noe Noah 2014 Cz dabing.avi
2014-11-20 18:17 - 2014-11-20 18:17 - 00000000 ___DC () C:\Users\xxx\Downloads\Originals
2014-11-20 18:16 - 2014-11-20 18:16 - 00088064 ___HC () C:\Users\xxx\Downloads\photothumb.db
2014-11-20 18:15 - 2014-11-20 18:15 - 00058016 ____C () C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-20 12:40 - 2011-06-26 07:45 - 00256000 ____C () C:\Windows\PEV.exe
2014-11-20 12:40 - 2010-11-07 18:20 - 00208896 ____C () C:\Windows\MBR.exe
2014-11-20 12:40 - 2009-04-20 05:56 - 00060416 ____C (NirSoft) C:\Windows\NIRCMD.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00518144 ____C (SteelWerX) C:\Windows\SWREG.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00406528 ____C (SteelWerX) C:\Windows\SWSC.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00098816 ____C () C:\Windows\sed.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00080412 ____C () C:\Windows\grep.exe
2014-11-20 12:40 - 2000-08-31 01:00 - 00068096 ____C () C:\Windows\zip.exe
2014-11-20 12:39 - 2014-11-22 02:09 - 00000000 ___DC () C:\Windows\erdnt
2014-11-20 12:39 - 2014-11-22 01:45 - 00000000 ___DC () C:\Qoobox
2014-11-20 12:38 - 2014-11-20 12:38 - 05598306 ___RC (Swearware) C:\Users\xxx\Desktop\ComboFix.exe
2014-11-19 19:27 - 2014-11-19 19:27 - 00013312 ___HC () C:\Users\xxx\Desktop\photothumb.db
2014-11-19 18:20 - 2014-11-19 19:26 - 1191654528 ____C () C:\Users\xxx\Downloads\STRÁŽCI GALAXIE 2014 CZ titulky BLURAY.avi
2014-11-18 19:52 - 2014-11-18 19:57 - 17372042 ____C () C:\Users\xxx\Downloads\Timmy Time S03E06 Baby Time Timmy (Mobile).3gp
2014-11-18 19:51 - 2014-11-18 19:53 - 06218877 ____C () C:\Users\xxx\Downloads\Timmy Time S03E12 Fireman Timmy (Mobile).3gp
2014-11-17 20:57 - 2014-11-17 21:54 - 1025509792 ____C () C:\Users\xxx\Downloads\V-zajetí-démonů-2013-DVDRip-CZ-Dabing.avi
2014-11-17 20:43 - 2014-11-17 20:43 - 00000386 ____C () C:\Users\xxx\Desktop\Vyměnitelný disk (F) – zástupce.lnk
2014-11-16 22:42 - 2014-11-16 22:20 - 00024064 ____C () C:\Windows\zoek-delete.exe
2014-11-16 22:21 - 2014-11-01 12:41 - 00008835 ____C () C:\zoek-results2014-11-01-114145.log
2014-11-16 22:19 - 2014-11-16 22:19 - 01294848 ____C () C:\Users\xxx\Downloads\zoek.exe
2014-11-16 16:46 - 2014-11-16 16:48 - 10056251 ____C () C:\Users\xxx\Desktop\Zábavné video o opiciach.3gp
2014-11-16 13:25 - 2014-11-16 13:25 - 01707532 ____C (Thisisu) C:\Users\xxx\Downloads\JRT.exe
2014-11-16 10:23 - 2014-11-16 10:24 - 14678104 ____C () C:\Users\xxx\Downloads\RogueKiller.exe
2014-11-16 10:03 - 2014-11-16 22:49 - 00001942 ____C () C:\Windows\PFRO.log
2014-11-15 20:16 - 2014-11-16 10:19 - 00114904 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-15 20:15 - 2014-11-15 20:15 - 00001020 ____C () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-15 20:15 - 2014-11-15 20:15 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-15 20:15 - 2014-11-15 20:15 - 00000000 ___DC () C:\Program Files\Malwarebytes Anti-Malware
2014-11-15 20:15 - 2014-10-01 11:11 - 00075480 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-15 20:15 - 2014-10-01 11:11 - 00051928 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-15 20:15 - 2014-10-01 11:11 - 00023256 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-15 20:14 - 2014-11-15 20:14 - 19828376 ____C (Malwarebytes Corporation ) C:\Users\xxx\Downloads\mbam-setup-2.0.3.1025(1).exe
2014-11-15 20:08 - 2014-11-15 20:08 - 02140160 ____C () C:\Users\xxx\Downloads\adwcleaner_4.101.exe
2014-11-15 19:57 - 2014-11-15 19:57 - 00448512 ____C (OldTimer Tools) C:\Users\xxx\Downloads\TFC(1).exe
2014-11-15 18:51 - 2014-11-15 18:51 - 00003106 ____C () C:\Users\xxx\Downloads\hijackthis.log
2014-11-15 18:48 - 2014-11-15 18:48 - 00388608 ____C (Trend Micro Inc.) C:\Users\xxx\Downloads\HijackThis.exe
2014-11-15 18:07 - 2014-11-15 18:07 - 00000000 ___DC () C:\ProgramData\Emsisoft
2014-11-15 17:58 - 2014-11-16 22:49 - 00000000 ___DC () C:\Program Files\Emsisoft Anti-Malware
2014-11-15 17:46 - 2014-11-15 18:16 - 00001340 ____C () C:\Windows\system32\.crusader
2014-11-15 17:36 - 2014-11-15 17:47 - 00000000 ___DC () C:\ProgramData\HitmanPro
2014-11-15 17:35 - 2014-11-15 17:36 - 10284408 ____C (SurfRight B.V.) C:\Users\xxx\Downloads\HitmanPro.exe
2014-11-15 17:21 - 2014-11-15 17:21 - 00267432 ____C () C:\Windows\system32\FNTCACHE.DAT
2014-11-15 17:06 - 2014-11-22 12:10 - 00057686 ____C () C:\Windows\setupact.log
2014-11-15 17:06 - 2014-11-15 17:06 - 00000000 ____C () C:\Windows\setuperr.log
2014-11-15 03:32 - 2014-11-15 03:32 - 00407040 ____C () C:\Users\xxx\Downloads\WebcamSchnappschuss.exe
2014-11-15 02:33 - 2014-11-15 02:33 - 00001211 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2014-11-15 02:33 - 2014-11-15 02:33 - 00000000 ___DC () C:\Windows\cs
2014-11-15 02:32 - 2014-11-15 02:32 - 00001280 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2014-11-15 02:31 - 2014-11-15 02:32 - 00000020 ____C () C:\Windows\řőŠ
2014-11-15 02:31 - 2014-11-15 02:31 - 00000000 ___DC () C:\Program Files\Microsoft SQL Server Compact Edition
2014-11-15 02:30 - 2014-11-15 02:30 - 00000000 ___DC () C:\Windows\PCHEALTH
2014-11-15 02:29 - 2014-11-15 02:31 - 00000000 ___DC () C:\Program Files\Windows Live
2014-11-15 02:26 - 2010-06-02 04:55 - 00527192 ____C (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2014-11-15 02:26 - 2010-06-02 04:55 - 00074072 ____C (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2014-11-15 02:26 - 2010-05-26 11:41 - 02106216 ____C (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2014-11-15 02:26 - 2010-05-26 11:41 - 00248672 ____C (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-11-15 02:24 - 2009-09-04 17:29 - 00453456 ____C (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2014-11-15 02:23 - 2006-11-29 13:06 - 03426072 ____C (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2014-11-15 02:21 - 2014-11-22 04:27 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Windows Live
2014-11-15 02:21 - 2014-11-15 02:21 - 00000000 ___DC () C:\Program Files\Common Files\Windows Live
2014-11-15 02:20 - 2014-11-15 02:20 - 01243336 ____C (společnost Microsoft Corporation) C:\Users\xxx\Downloads\wlsetup-web.exe
2014-11-15 01:59 - 2014-11-03 10:04 - 00043688 ____C (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2014-11-15 01:56 - 2014-11-15 01:56 - 00728960 ____C (Enigma Software Group USA, LLC.) C:\Users\xxx\Downloads\SpyHunter-installer.exe
2014-11-14 18:45 - 2014-11-14 18:46 - 00037875 ____C () C:\Users\xxx\Downloads\stahování.htm
2014-11-14 01:12 - 2014-11-15 10:07 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\dvdcss
2014-11-14 01:08 - 2014-11-14 01:08 - 00001856 ____C () C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2014-11-14 01:08 - 2014-11-14 01:08 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2014-11-14 01:04 - 2014-11-15 10:28 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\DAEMON Tools Lite
2014-11-14 01:04 - 2014-11-14 01:04 - 00243128 ____C (Disc Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2014-11-14 01:04 - 2014-11-14 01:04 - 00000000 ___DC () C:\Program Files\DAEMON Tools Lite
2014-11-14 01:03 - 2014-11-14 01:11 - 00000000 ___DC () C:\ProgramData\DAEMON Tools Lite
2014-11-14 00:59 - 2014-11-14 00:59 - 12891208 ____C (Ashampoo GmbH & Co. KG ) C:\Users\xxx\Downloads\ashampoo_burning_studio_6_free_6.84_13471.exe
2014-11-14 00:53 - 2014-11-14 00:53 - 07716056 ____C (Alcohol Soft Development Team) C:\Users\xxx\Downloads\Alcohol120_trial_2.0.3.6839.exe
2014-11-13 21:15 - 2014-11-14 00:44 - 3737485468 ____C () C:\Users\xxx\Downloads\Bee-Gees---One-Night-Only-live-DVD-(1997).nrg
2014-11-10 15:00 - 2014-11-10 15:01 - 00000000 ___DC () C:\ks
2014-11-09 11:06 - 2014-11-09 11:06 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kid Key Lock
2014-11-09 11:06 - 2014-11-09 11:06 - 00000000 ___DC () C:\Program Files\100dof_kidkeylock
2014-11-07 13:22 - 2014-11-07 13:22 - 10156325 ____C () C:\Users\xxx\Downloads\N.E.R.D. _ Hypnotize U.flv
2014-11-07 13:21 - 2014-11-07 13:21 - 10156325 ____C () C:\Users\xxx\Downloads\Youngblood Hawke _ We Come Running (1).flv
2014-11-07 12:57 - 2014-11-07 13:25 - 00000000 ___DC () C:\FFOutput
2014-11-07 12:56 - 2014-11-07 12:56 - 00001116 ____C () C:\Users\xxx\Desktop\Format Factory.lnk
2014-11-07 12:56 - 2014-11-07 12:56 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2014-11-07 12:50 - 2014-11-07 12:50 - 00000000 ___DC () C:\Program Files\FreeTime
2014-11-06 21:13 - 2014-11-06 22:18 - 1159985152 ____C () C:\Users\xxx\Downloads\Koleje osudu 2013 CZ dabing.avi
2014-11-06 18:49 - 2014-11-06 19:37 - 870252544 ____C () C:\Users\xxx\Downloads\Volani---The-Calling-2014-cz.avi
2014-11-06 18:43 - 2014-11-06 19:36 - 964947968 ____C () C:\Users\xxx\Downloads\SOUSEDI 2014 CZ dabing.avi
2014-11-06 13:20 - 2014-11-06 13:20 - 00014424 ____C () C:\Windows\system32\results.xml
2014-11-05 09:30 - 2014-11-06 13:37 - 00000512 ____C () C:\PhysicalMBR.bin
2014-11-05 01:59 - 2014-11-05 02:01 - 27410773 ____C () C:\Users\xxx\Downloads\Sex-s-naprosto-opilou-a-nadrženou-kámoškou-na-párty.mp4
2014-11-05 00:40 - 2014-11-05 00:40 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Tonium
2014-11-05 00:35 - 2014-11-05 00:35 - 00000000 ___DC () C:\Users\xxx\Downloads\PME-Win-2.0.2.14170
2014-11-05 00:30 - 2014-11-05 00:31 - 33973728 ____C () C:\Users\xxx\Downloads\PME-Win-2.0.2.14170.zip
2014-11-04 23:50 - 2014-11-04 23:50 - 00000000 ___DC () C:\Program Files\trend micro
2014-11-04 23:22 - 2014-11-04 23:36 - 00000000 ___DC () C:\Program Files\Pointstone
2014-11-04 23:17 - 2014-11-04 23:17 - 02046216 ____C (Pointstone Software, LLC) C:\Users\xxx\Downloads\MemOptimizerSetup.exe
2014-11-04 22:31 - 2014-11-04 22:31 - 00000000 ___DC () C:\Program Files\CONEXANT
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\Windows\system32\Lang
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\ProgramData\IntelDLM
2014-11-04 22:20 - 2014-11-04 22:20 - 00000000 ___DC () C:\Intel
2014-11-04 22:20 - 2009-10-02 14:34 - 08198680 ____C (Intel(R) Corporation) C:\Windows\system32\TVWSetup.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00672792 ____C (Intel Corporation) C:\Windows\system32\igfxcfg.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00252952 ____C (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00173592 ____C (Intel Corporation) C:\Windows\system32\hkcmd.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00173080 ____C (Intel Corporation) C:\Windows\system32\igfxext.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00150552 ____C (Intel Corporation) C:\Windows\system32\igfxpers.exe
2014-11-04 22:20 - 2009-10-02 14:34 - 00141848 ____C (Intel Corporation) C:\Windows\system32\igfxtray.exe
2014-11-04 22:16 - 2014-11-04 22:16 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Intel
2014-11-04 22:11 - 2014-11-04 22:11 - 00019456 ____C () C:\Users\xxx\Downloads\launcher32.dll
2014-11-04 22:04 - 2014-11-04 22:04 - 00023456 ____C (Phoenix Technologies) C:\Windows\system32\Drivers\DrvAgent32.sys
2014-11-04 20:43 - 2014-11-04 20:43 - 00000000 ___DC () C:\Users\xxx\Downloads\MemTest
2014-11-03 15:36 - 2014-11-05 01:18 - 00000269 ____C () C:\Users\xxx\Documents\hizs.txt
2014-11-03 13:49 - 2014-11-03 14:51 - 1134336000 ____C () C:\Users\xxx\Downloads\Godzilla 2014 CZ dabing.avi
2014-11-03 13:19 - 2014-11-03 13:19 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Adobe
2014-11-03 11:58 - 2014-11-03 12:24 - 1303578624 ____C () C:\Users\xxx\Downloads\Need for Speed 2014 CZ dabing.avi
2014-11-01 10:26 - 2014-11-21 16:53 - 00000000 ___DC () C:\Users\xxx\AppData\Local\CrashDumps
2014-11-01 10:25 - 2014-11-16 22:49 - 00007828 ____C () C:\zoek-results.log
2014-11-01 10:22 - 2014-11-16 22:37 - 00000000 ___DC () C:\zoek_backup
2014-10-31 13:44 - 2014-11-16 20:27 - 00034808 ____C () C:\Windows\system32\Drivers\TrueSight.sys
2014-10-31 13:44 - 2014-10-31 13:44 - 00000000 ___DC () C:\ProgramData\RogueKiller
2014-10-31 13:22 - 2014-10-31 13:22 - 00000000 ___DC () C:\Windows\ERUNT
2014-10-30 14:02 - 2014-10-30 14:02 - 00001053 ____C () C:\Users\Public\Desktop\Opera.lnk
2014-10-30 14:02 - 2014-10-30 14:02 - 00001053 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-10-30 13:23 - 2014-10-30 13:23 - 00000049 ____C () C:\loi.txt
2014-10-30 11:48 - 2014-10-30 11:48 - 00000000 ___DC () C:\ProgramData\Malwarebytes
2014-10-30 11:42 - 2010-08-30 08:34 - 00536576 ____C (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-10-30 11:41 - 2014-11-16 10:13 - 00000000 ___DC () C:\AdwCleaner
2014-10-30 11:21 - 2014-10-30 11:21 - 19828376 ____C (Malwarebytes Corporation ) C:\Users\xxx\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-30 11:18 - 2014-10-30 11:18 - 00448512 ____C (OldTimer Tools) C:\Users\xxx\Downloads\TFC.exe
2014-10-30 10:09 - 2014-11-22 02:09 - 00000000 ___DC () C:\Program Files\Mozilla Firefox
2014-10-29 19:16 - 2014-11-20 21:55 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\PhotoScape
2014-10-29 19:15 - 2014-10-29 19:16 - 00000000 ___DC () C:\Program Files\PhotoScape
2014-10-29 19:15 - 2014-10-29 19:15 - 00000949 ____C () C:\Users\xxx\Desktop\PhotoScape.lnk
2014-10-29 19:15 - 2014-10-29 19:15 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2014-10-28 09:16 - 2014-10-30 14:03 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Opera Software
2014-10-28 09:16 - 2014-10-30 14:03 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Opera Software
2014-10-28 08:53 - 2014-10-28 08:53 - 00000000 ___DC () C:\Windows\pss
2014-10-28 02:21 - 2014-10-28 02:21 - 00701104 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-10-28 02:21 - 2014-10-28 02:21 - 00071344 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-10-28 01:44 - 2014-11-22 05:12 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\vlc
2014-10-28 01:43 - 2014-10-28 01:43 - 00000984 ____C () C:\Users\Public\Desktop\VLC media player.lnk
2014-10-28 01:43 - 2014-10-28 01:43 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-10-28 01:42 - 2014-10-28 01:42 - 00000000 ___DC () C:\Program Files\VideoLAN
2014-10-26 19:06 - 2014-10-27 19:00 - 00002441 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-10-26 19:06 - 2014-10-26 19:06 - 00001949 ____C () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-10-26 19:05 - 2014-10-27 18:57 - 00000000 ___DC () C:\ProgramData\Adobe
2014-10-26 19:05 - 2014-10-26 19:06 - 00000000 ___DC () C:\Program Files\Common Files\Adobe
2014-10-26 19:05 - 2014-10-26 19:05 - 00000000 ___DC () C:\Program Files\Adobe
2014-10-25 20:33 - 2014-10-25 20:33 - 00000925 ____C () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-25 20:33 - 2014-10-25 20:33 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-10-25 20:33 - 2014-10-25 20:33 - 00000000 ___DC () C:\Program Files\CCleaner
2014-10-25 19:37 - 2014-10-25 19:37 - 00007597 ____C () C:\Users\xxx\AppData\Local\Resmon.ResmonCfg
2014-10-25 18:59 - 2014-10-25 18:59 - 00000000 _SHDC () C:\Users\xxx\AppData\Local\EmieUserList
2014-10-25 18:59 - 2014-10-25 18:59 - 00000000 _SHDC () C:\Users\xxx\AppData\Local\EmieSiteList
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-22 11:06 - 2010-11-20 22:01 - 01583226 ____C () C:\Windows\system32\PerfStringBackup.INI
2014-11-22 11:03 - 2012-02-05 02:24 - 01852864 ____C () C:\Windows\WindowsUpdate.log
2014-11-22 10:19 - 2012-04-01 11:01 - 00000000 ___DC () C:\Program Files\Opera
2014-11-22 10:19 - 2009-07-14 05:34 - 00026576 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-22 10:19 - 2009-07-14 05:34 - 00026576 ___HC () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-22 10:11 - 2009-07-14 05:53 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT
2014-11-22 10:00 - 2012-06-25 17:17 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Skype
2014-11-22 02:10 - 2012-02-05 02:30 - 00000000 __RDC () C:\Users\xxx
2014-11-22 02:10 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\wfp
2014-11-22 02:09 - 2012-08-22 15:38 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Facebook
2014-11-22 02:09 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\NDF
2014-11-22 02:09 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\registration
2014-11-16 22:39 - 2012-02-12 11:02 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Google
2014-11-15 02:30 - 2009-07-14 03:37 - 00000000 ___DC () C:\Program Files\Common Files\microsoft shared
2014-11-15 02:08 - 2012-06-25 17:15 - 00000000 __RDC () C:\Program Files\Skype
2014-11-10 15:14 - 2012-02-12 16:00 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DSPlayer v0.889 lite
2014-11-09 14:55 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\Cursors
2014-11-09 14:21 - 2009-07-14 03:04 - 00000505 ____C () C:\Windows\win.ini
2014-11-04 22:09 - 2013-08-29 14:22 - 00000000 ___DC () C:\Program Files\rc
2014-11-04 22:09 - 2012-02-12 17:24 - 00000000 ___DC () C:\Games
2014-11-04 22:09 - 2009-07-14 05:52 - 00000000 __RDC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-11-04 20:32 - 2009-07-14 03:37 - 00000000 ___DC () C:\Windows\system32\LogFiles
2014-11-04 14:30 - 2012-02-12 10:21 - 00229000 ____C (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-03 19:27 - 2012-08-22 15:38 - 00000920 ____C () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job
2014-11-03 19:27 - 2012-08-22 15:38 - 00000898 ____C () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job
2014-11-03 15:12 - 2012-06-26 18:13 - 00006656 ____C () C:\Users\xxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-10-30 11:39 - 2012-07-13 13:27 - 00001007 ____C () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-10-29 12:43 - 2012-09-27 17:23 - 00000000 ___DC () C:\Webcam eye 312
2014-10-28 01:38 - 2012-10-05 08:45 - 00000000 ___DC () C:\Program Files\GRETECH
2014-10-26 19:09 - 2012-02-12 10:16 - 00000000 ___DC () C:\Users\xxx\AppData\Roaming\Adobe
2014-10-25 21:17 - 2012-02-12 10:59 - 00000000 ___DC () C:\ProgramData\AVAST Software
2014-10-25 20:49 - 2012-11-22 13:16 - 00000000 ___DC () C:\Users\xxx\AppData\Local\Unity
2014-10-25 20:35 - 2012-02-05 02:18 - 00000000 ___DC () C:\Windows\Panther
2014-10-25 20:18 - 2012-02-05 02:37 - 00000000 __HDC () C:\Program Files\InstallShield Installation Information
2014-10-25 19:07 - 2012-02-12 11:02 - 00000000 ___DC () C:\Program Files\Google
2014-10-25 19:02 - 2012-03-19 11:39 - 00000000 ___DC () C:\Windows\Minidump
Some content of TEMP:
====================
C:\Users\xxx\AppData\Local\temp\HitmanPro.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-15 05:18
==================== End Of Log ============================
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 21-11-2014
Ran by xxx at 2014-11-22 08:35:21
Running from C:\Users\xxx\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_HDAUDIO) (Version: 4.15.0.0 - Conexant)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
FormatFactory 3.3.5.0 (HKLM\...\FormatFactory) (Version: 3.3.5.0 - Format Factory)
Fotogalerie (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
HP Quick Launch Buttons (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Kid Key Lock 2.4.0.0 (HKLM\...\Kid Key Lock_is1) (Version: - 100dof)
Malwarebytes Anti-Malware verze 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 33.1 (x86 cs) (HKLM\...\Mozilla Firefox 33.1 (x86 cs)) (Version: 33.1 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
Opera Stable 25.0.1614.71 (HKLM\...\Opera 25.0.1614.71) (Version: 25.0.1614.71 - Opera Software ASA)
Photo Common (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Photo Gallery (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
PhotoScape (HKLM\...\PhotoScape) (Version: - )
Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-223422653-1716354506-2496423225-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-223422653-1716354506-2496423225-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\xxx\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
==================== Restore Points =========================
20-11-2014 20:53:20 Operace obnovení
21-11-2014 15:54:52 Windows Update
22-11-2014 01:16:46 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2014-11-16 22:21 - 00000840 ___AC C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1E203380-03B0-41C8-8E0B-1A045D84B5C5} - System32\Tasks\{FA90DEDC-AD35-4B2B-ADD5-D0BAA8A3F0A0} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {20E8473B-6DCB-43FD-B3CD-139B8653A616} - System32\Tasks\{F8823EE9-9A6E-4CCD-BDB0-204BB7FDD0ED} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {22270C22-3EDB-4C58-9DC5-F5CE7788AC44} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-223422653-1716354506-2496423225-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {4BA9497B-A24D-49E0-A187-739E86084E88} - System32\Tasks\{81E22591-3B07-47EA-A3E0-F5C7DFC3274F} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {95983B2B-7AB5-46F6-9695-3785EEEFCCA2} - System32\Tasks\{C1EF6C42-85DF-4810-BC4B-60CAFBCDC7FE} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {9A70A8A2-B9E2-4865-9185-B27D6658404F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {B817D556-FECF-4EAC-A360-6A5A5CDA17BB} - System32\Tasks\{8C595FD3-4F37-41B0-8956-AA199CA89F4C} => Firefox.exe http://ui.skype.com/ui/0/5.10.0.114/cs/ ... age=tsMain
Task: {BD916012-502A-4445-9937-785A20BE521B} - System32\Tasks\{6511875B-C786-4FDB-89C9-8EB101602787} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {C0271658-F1C8-4336-A68D-B079195A5995} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {CB8C96C6-0A2E-4B73-90D4-5AF039D0F3C2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-223422653-1716354506-2496423225-1000
Task: {E4FF2D33-AAF8-423F-A223-556AEAB2ADE9} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-223422653-1716354506-2496423225-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {EA525BB2-7203-44EA-BF28-C4E77EBFA332} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)
Task: {EA997836-ED89-4583-AC5F-6D357018CB4E} - System32\Tasks\Opera scheduled Autoupdate 1414674161 => C:\Program Files\Opera\launcher.exe [2014-11-14] (Opera Software)
Task: {F12D831D-467E-421A-9EB4-3E70FAFDE5C4} - System32\Tasks\{9A867533-0700-490C-89F0-FB282EF8BF90} => C:\Program Files\Opera\launcher.exe [2014-11-14] (Opera Software)
Task: {F5DF8A49-9DA3-4FC0-AE3A-C67DC7C58807} - System32\Tasks\{9B61E7AD-A246-4F30-8458-7565C0E5231F} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {F90CC8BA-7799-41DC-9BC7-6C023F5F3C84} - System32\Tasks\{602209E4-BCFF-4C8B-B934-76F542A620C1} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-10-30 10:09 - 2014-11-11 10:15 - 03649648 ____C () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-10-28 02:21 - 2014-10-28 02:21 - 16832176 ____C () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
========================= Accounts: ==========================
Administrator (S-1-5-21-223422653-1716354506-2496423225-500 - Administrator - Disabled)
Guest (S-1-5-21-223422653-1716354506-2496423225-501 - Limited - Disabled)
xxx (S-1-5-21-223422653-1716354506-2496423225-1000 - Administrator - Enabled) => C:\Users\xxx
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/22/2014 02:11:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/22/2014 02:03:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/22/2014 01:49:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Ran by xxx at 2014-11-22 08:35:21
Running from C:\Users\xxx\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.09) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated)
CCleaner (HKLM\...\CCleaner) (Version: 4.18 - Piriform)
Conexant HD Audio (HKLM\...\CNXT_HDAUDIO) (Version: 4.15.0.0 - Conexant)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
FormatFactory 3.3.5.0 (HKLM\...\FormatFactory) (Version: 3.3.5.0 - Format Factory)
Fotogalerie (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
HP Quick Launch Buttons (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Kid Key Lock 2.4.0.0 (HKLM\...\Kid Key Lock_is1) (Version: - 100dof)
Malwarebytes Anti-Malware verze 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 33.1 (x86 cs) (HKLM\...\Mozilla Firefox 33.1 (x86 cs)) (Version: 33.1 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (Version: 16.4.1108.0727 - Microsoft) Hidden
Opera Stable 25.0.1614.71 (HKLM\...\Opera 25.0.1614.71) (Version: 25.0.1614.71 - Opera Software ASA)
Photo Common (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Photo Gallery (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
PhotoScape (HKLM\...\PhotoScape) (Version: - )
Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-223422653-1716354506-2496423225-1000_Classes\CLSID\{1FD1FE74-9E3C-4C1C-AEEB-AAB592AD770F}\localserver32 -> C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
CustomCLSID: HKU\S-1-5-21-223422653-1716354506-2496423225-1000_Classes\CLSID\{5E71E4F3-E8C7-4906-9626-973E418762B6}\InprocServer32 -> C:\Users\xxx\AppData\Local\Facebook\Update\1.2.205.0\goopdate.dll (Facebook Inc.)
==================== Restore Points =========================
20-11-2014 20:53:20 Operace obnovení
21-11-2014 15:54:52 Windows Update
22-11-2014 01:16:46 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2014-11-16 22:21 - 00000840 ___AC C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {1E203380-03B0-41C8-8E0B-1A045D84B5C5} - System32\Tasks\{FA90DEDC-AD35-4B2B-ADD5-D0BAA8A3F0A0} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {20E8473B-6DCB-43FD-B3CD-139B8653A616} - System32\Tasks\{F8823EE9-9A6E-4CCD-BDB0-204BB7FDD0ED} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {22270C22-3EDB-4C58-9DC5-F5CE7788AC44} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-223422653-1716354506-2496423225-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {4BA9497B-A24D-49E0-A187-739E86084E88} - System32\Tasks\{81E22591-3B07-47EA-A3E0-F5C7DFC3274F} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {95983B2B-7AB5-46F6-9695-3785EEEFCCA2} - System32\Tasks\{C1EF6C42-85DF-4810-BC4B-60CAFBCDC7FE} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {9A70A8A2-B9E2-4865-9185-B27D6658404F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {B817D556-FECF-4EAC-A360-6A5A5CDA17BB} - System32\Tasks\{8C595FD3-4F37-41B0-8956-AA199CA89F4C} => Firefox.exe http://ui.skype.com/ui/0/5.10.0.114/cs/ ... age=tsMain
Task: {BD916012-502A-4445-9937-785A20BE521B} - System32\Tasks\{6511875B-C786-4FDB-89C9-8EB101602787} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {C0271658-F1C8-4336-A68D-B079195A5995} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {CB8C96C6-0A2E-4B73-90D4-5AF039D0F3C2} - System32\Tasks\Games\UpdateCheck_S-1-5-21-223422653-1716354506-2496423225-1000
Task: {E4FF2D33-AAF8-423F-A223-556AEAB2ADE9} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-223422653-1716354506-2496423225-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {EA525BB2-7203-44EA-BF28-C4E77EBFA332} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-09-26] (Piriform Ltd)
Task: {EA997836-ED89-4583-AC5F-6D357018CB4E} - System32\Tasks\Opera scheduled Autoupdate 1414674161 => C:\Program Files\Opera\launcher.exe [2014-11-14] (Opera Software)
Task: {F12D831D-467E-421A-9EB4-3E70FAFDE5C4} - System32\Tasks\{9A867533-0700-490C-89F0-FB282EF8BF90} => C:\Program Files\Opera\launcher.exe [2014-11-14] (Opera Software)
Task: {F5DF8A49-9DA3-4FC0-AE3A-C67DC7C58807} - System32\Tasks\{9B61E7AD-A246-4F30-8458-7565C0E5231F} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
Task: {F90CC8BA-7799-41DC-9BC7-6C023F5F3C84} - System32\Tasks\{602209E4-BCFF-4C8B-B934-76F542A620C1} => Firefox.exe http://ui.skype.com/ui/0/6.14.0.104/cs/ ... rogressBar
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-10-30 10:09 - 2014-11-11 10:15 - 03649648 ____C () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-10-28 02:21 - 2014-10-28 02:21 - 16832176 ____C () C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_189.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Skype => "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
========================= Accounts: ==========================
Administrator (S-1-5-21-223422653-1716354506-2496423225-500 - Administrator - Disabled)
Guest (S-1-5-21-223422653-1716354506-2496423225-501 - Limited - Disabled)
xxx (S-1-5-21-223422653-1716354506-2496423225-1000 - Administrator - Enabled) => C:\Users\xxx
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/22/2014 02:11:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/22/2014 02:03:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (11/22/2014 01:49:39 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
- Orcus
- člen Security týmu
-
Elite Level 10.5
- Příspěvky: 10645
- Registrován: duben 10
- Bydliště: Okolo rostou 3 růže =o)
- Pohlaví:
- Stav:
Offline
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusť FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
Kód: Vybrat vše
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {6b43620d-50f4-4094-aea5-bd840890f757} URL = http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {7904d8f0-7208-4462-95d8-b4887ed9d3a5} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {ea8f2e38-3cb0-42a5-ad58-0c729227f856} URL = http://www.firmy.cz/phr/{searchTerms}?sourceid=IEListicka_12
ask: {22270C22-3EDB-4C58-9DC5-F5CE7788AC44} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-223422653-1716354506-2496423225-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {9A70A8A2-B9E2-4865-9185-B27D6658404F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {C0271658-F1C8-4336-A68D-B079195A5995} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusť FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Láska hřeje, ale uhlí je uhlí.
Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.

Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.
Pár rad k bezpečnosti PC.
Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix
Pokud budete spokojeni , můžete podpořit naše fórum.
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
FRst hlásí "no fixlist.txt found
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Odinstaluj:
Emsisoft Anti-Malware
následující udělej v nouz. režimu:
Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Tcpip\..\Interfaces\{AEB3D5D8-CE48-424E-AF3F-D04C86A5B07F}: [NameServer] 208.67.222.222,208.67.220.220 -- USA? znáš tu IP??
C:\Windows\řőŠ
C:\ks
znáš ty složky?
Emsisoft Anti-Malware
následující udělej v nouz. režimu:
Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.
Kód: Vybrat vše
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {15b2313e-5558-11e1-a333-001b388cbe5c} - E:\AutoRun.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8ab7-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {18eb8aba-5c53-11e4-ba60-001b388cbe5c} - E:\StartVMCLite.exe
HKU\S-1-5-21-223422653-1716354506-2496423225-1000\...\MountPoints2: {e080bcab-c91d-11e1-9360-001b388cbe5c} - E:\application\Nokia_Internet_Modem.exe
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {6b43620d-50f4-4094-aea5-bd840890f757} URL = http://www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {7904d8f0-7208-4462-95d8-b4887ed9d3a5} URL = http://www.mapy.cz/?query={searchTerms}&sourceid=IEListicka_12
SearchScopes: HKU\S-1-5-21-223422653-1716354506-2496423225-1000 -> {ea8f2e38-3cb0-42a5-ad58-0c729227f856} URL = http://www.firmy.cz/phr/{searchTerms}?sourceid=IEListicka_12
Task: {9A70A8A2-B9E2-4865-9185-B27D6658404F} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
Task: {C0271658-F1C8-4336-A68D-B079195A5995} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-22] (Facebook Inc.)
C:\32788R22FWJFW
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000Core.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-223422653-1716354506-2496423225-1000UA.job => C:\Users\xxx\AppData\Local\Facebook\Update\FacebookUpdate.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).
Ulož jej na na plochu jako fixlist.txt
Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Tcpip\..\Interfaces\{AEB3D5D8-CE48-424E-AF3F-D04C86A5B07F}: [NameServer] 208.67.222.222,208.67.220.220 -- USA? znáš tu IP??
C:\Windows\řőŠ
C:\ks
znáš ty složky?
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Ip adresu neznam...řoŠ nejde otevřit ks je log jsou tam nějake zpravy o zaznamu psaní, takže program na zaznam ale nemužu ho najit ani jak se jmenuje a začal se mi přehřivat notas cca po 10min vypne jako kdyby nešl větraček , ale vím že jel, emisoft jsem instaloval ja ale zjistil jsme že se podivně chova a měl zatěž na ram tak jsem ho odinstaloval před 1-2 týdny ale pišeš že ho tam mám , nic méně ho nemužu najít ani ccleaner mi ho neukazuje
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
řoŠ šel otevřit a bylo v něm napsano toto:[KeyList]
Count=0
emisoft jsem našel program files jenom jako složku
Count=0
emisoft jsem našel program files jenom jako složku
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
frst nejde ani v nouzovem režimu pořad to haže hlašku no fixlist
- jaro3
- člen Security týmu
-
Guru Level 15
- Příspěvky: 43294
- Registrován: červen 07
- Bydliště: Jižní Čechy
- Pohlaví:
- Stav:
Offline
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Emsisoft Anti-Malware odinstaluj tímto:
http://tmp.emsisoft.com/fw/emsiclean.exe
Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
http://tmp.emsisoft.com/fw/emsiclean.exe
Stáhni si OTL by OldTimer
na plochu. Ujisti se , že máš zavřena všechna ostatní okna a poklepej na ikonu OTL.Nahoře v okně pod Výstup klikni na minimální výstup.Pod Běžné registry změň na Vše. Zatrhni Kontrola na havěť “LOP“ a Kontrola na havěť “ Purity“ . Klikni na Prohledat. Všechny ostatní nastavení ponech jak jsou. Sken může trvat dlouho, až skončí otevřou se dva logy:
OTL.Txt
Extras.Txt
Jsou uloženy ve stejném místě jako OTL. Oba logy sem prosím zkopíruj.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
Po te odinstalačce emisoftu a restartu NTB se mi ten větrak začal točit takže znovu chladí
Re: Vysoka zatěž ram ,zasekáváni prohlížeču
******************************************************
* Scanning for traces of supported Emsisoft products *
******************************************************
Service/Driver:
cleanhlp (C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys)
Context Menu Handler:
Registry:
Folder:
C:\Program Files\Emsisoft Anti-Malware\
Scan finished!
******************************************************
* Removing selected Emsisoft product traces *
******************************************************
User requested to uninstall service "cleanhlp" ...
The service has been removed successfully!
User requested to delete the folder "C:\Program Files\Emsisoft Anti-Malware\" ...
"C:\Program Files\Emsisoft Anti-Malware\a2email.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2networks.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2policies.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2rules.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2settings.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2whitelist.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\2c8aa6e7-e86f-4ddd-9806-8ca1884a28a8.EQF" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\59ce6963-ff23-4d9e-a7d3-96e7f30adcca.EQF" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\" deleted successfully!
The removal process finished!
* Scanning for traces of supported Emsisoft products *
******************************************************
Service/Driver:
cleanhlp (C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys)
Context Menu Handler:
Registry:
Folder:
C:\Program Files\Emsisoft Anti-Malware\
Scan finished!
******************************************************
* Removing selected Emsisoft product traces *
******************************************************
User requested to uninstall service "cleanhlp" ...
The service has been removed successfully!
User requested to delete the folder "C:\Program Files\Emsisoft Anti-Malware\" ...
"C:\Program Files\Emsisoft Anti-Malware\a2email.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2networks.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2policies.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2rules.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2settings.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\a2whitelist.ini.backup" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\2c8aa6e7-e86f-4ddd-9806-8ca1884a28a8.EQF" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\59ce6963-ff23-4d9e-a7d3-96e7f30adcca.EQF" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\Quarantine\" deleted successfully!
"C:\Program Files\Emsisoft Anti-Malware\" deleted successfully!
The removal process finished!
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 97 hostů