Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 13 srp 2015 15:42

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Pak klikni na "Prohledat " ,po jeho skončení:

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)
(musíš dát myší zatržítko do toho čtverečku vlevo od registru ap.)


- Klikni na "Smazat"
- Počkej, dokud Status box nezobrazí " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni antivir i firewall.
Stáhni
Zoek.exe

a uloz si ho na plochu.
Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor , náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

Vlož nový log z HJT + informuj o problémech.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 13 srp 2015 16:55

RogueKiller V10.10.0.0 [Aug 11 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.10240) 32 bits version
Spuštěno : Normální režim
Uživatel : Petr [Práva správce]
Started from : C:\Users\Petr\Desktop\RogueKiller.exe
Mód : Smazat -- Datum : 08/13/2015 16:24:14

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 11 ¤¤¤
[PUM.HomePage] HKEY_USERS\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.seznam.cz/ -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_BB81\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_690D\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_BB81\ControlSet003\Services\Tcpip\Parameters | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{c6846616-3e73-45d0-840e-dae156dada32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c6846616-3e73-45d0-840e-dae156dada32} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_BB81\ControlSet002\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_D_690D\ControlSet003\Services\Tcpip\Parameters\Interfaces\{48B26D70-1381-4150-B132-B1F047F4A497} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()
[PUM.Dns] HKEY_LOCAL_MACHINE\RK_System_ON_H_BB81\ControlSet003\Services\Tcpip\Parameters\Interfaces\{903B650C-63A4-42E4-BAD6-EAC2B1AC0AC3} | DhcpNameServer : 213.46.172.37 213.46.172.36 ([-][CZECH REPUBLIC (CZ)]) -> Nahrazeno ()

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 1 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost Smazáno

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 18 ¤¤¤
[FIREFX:Addon] g82kcs7k.default-1430921114877 : EPUBReader [{5384767E-00D9-40E9-B72F-9CC39D655D6F}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Memory Fox [{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : about:addons-memory [about-addons-memory@tn123.org] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Pomocník skrývání prvk? pro Adblock Plus [elemhidehelper@adblockplus.org] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Ghostery [firefox@ghostery.com] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Classic Theme Restorer (Customize UI) [ClassicThemeRestorer@ArisT2Noia4dev] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Tab Mix Plus [{dc572301-7619-498c-a57d-39143191b318}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : ProxTube - Unblock YouTube [ich@maltegoetz.de] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : NoScript Security Suite [{73a6fe31-595d-460b-a920-fcc0f8843232}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Flagfox [{1018e4d6-728f-4b20-ad56-37578a4de76b}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Thumbnail Zoom Plus [thumbnailZoom@dadler.github.com] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Download Manager Tweak [{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Save-To-Read [save2read@konstantin.plotnikov] -> Smazáno
[PUP][FIREFX:Addon] g82kcs7k.default-1430921114877 : Seznam li?ti?ka [{ea614400-e918-4741-9a97-7a972ff7c30b}] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Restart My Fox [Restart-My-Fox@8pecxstudios.com] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Freemake Video Downloader Plugin [fmdownloader@gmail.com] -> Smazáno
[FIREFX:Addon] g82kcs7k.default-1430921114877 : Freemake Youtube Download Button [ytfmdownloader@gmail.com] -> Smazáno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000DL002-9TT153 ATA Device +++++
--- User ---
[MBR] 2e92f243d9cda3df34ee8b0f7197a587
[BSP] 6ea2a0a3240d75624aa44b632b008c0d : Empty|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 250003 MB [Windows XP Bootstrap | Windows XP Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 512007615 | Size: 703863 MB [Windows XP Bootstrap | Windows XP Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: ST3320620AS ATA Device +++++
--- User ---
[MBR] 3d587ea86aab753af1ae05276d8313d8
[BSP] 84ca8f005dac36c956db86d60d557f65 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 149997 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 307195904 | Size: 155245 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: KINGSTON SHFS37A120G ATA Device +++++
--- User ---
[MBR] d6528846718121a403e533f444507270
[BSP] 33341d9755143a87c8bdd92eb2c0b221 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114471 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 13 srp 2015 16:55

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Petr on 13.08.2015 at 16:26:41,28.
Microsoft Windows 10 Home 10.0.10240 x86
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Petr\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

13.08.2015 16:28:07 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\Program Files\Common Files\AV deleted successfully
C:\PROGRA~2\Comms deleted successfully
C:\PROGRA~2\Shared Space deleted successfully
C:\PROGRA~2\SoftwareDistribution deleted successfully
C:\Users\Public\AppData\Local deleted successfully
C:\Users\Petr\AppData\Local\CrashDumps deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\prefs.js:
user_pref("browser.startup.homepage", "https://www.seznam.cz/");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1642_.backup

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1642_.backup

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs__1642_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\searchplugins\torrents-search.xml deleted
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\jetpack deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\0khh5aex.default-1427958703254
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"ytfmdownloader@gmail.com"="C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com" [07.02.2014 10:31]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
- esk slovnk pro kontrolu pravopisu - %ProfilePath%\extensions\cs@dictionaries.addons.mozilla.org

ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\SeaMonkey\Profiles\s23qpowu.default
- DOM-granskaren DOM Inspector - %ProfilePath%\extensions\inspector@mozilla.org.xpi
- ChatZilla - %ProfilePath%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}.xpi

AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
0A1788EE70EF444DABA1E958092F4B85 - C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll - Adobe Acrobat
52CE0DBFD9738AE528CF525A0367EBEB - C:\Program Files\VideoLAN\VLC\npvlc.dll - VLC Web Plugin
1F352B5944AF5C2204D9EFF7F845C5AF - C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll - Google Update
8E9A08E2092B3E1ADFF3C46BC1A5124B - C:\Program Files\TVUPlayer\npTVUAx.dll - TVU Web Player for FireFox
0A7CFC4EE9CC3206B1DC522FCB8C3DB1 - C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll - Silverlight Plug-In
C7090AB2D8473D12D48B818FC1FE7AF9 - C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll - Java(TM) Platform SE 8 U51
95479782C832632116E0FC0C8373F43E - C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npdeployJava1.dll - Java Deployment Toolkit 8.0.510.16
0205ADAFFDDF04F0F69200E5CFB5FFD9 - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll - Google Earth Plugin
1DE714BB4BB48B10BC94FF84C9BC6471 - C:\Program Files\DivX\DivX Web Player\npdivx32.dll - DivX Web Player
E37EAD09D28AE19D8A39B6A95F47513A - C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll - Shockwave for Director / Shockwave for Director
FD82108FD60B63010325D9AF6F00AF99 - C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_209.dll - Shockwave Flash
0B8378EA70622A6F3EC50CC4AF62764C - C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrlui.dll - Microsoft® Silverlight


==== Chromium Look ======================

Google Chrome Version: 44.0.2403.155



==== Chromium Startpages ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences
led_by_oem":false},"pjkljhegncpnkpknbcohdijeoejaedia":{"ack_external":true,"active_permissions":{"api":["notifications"],"manifest_permissions":[]},"app_launcher_ordinal":"z","commands":{},"content_settings":[],"creation_flags":137,"events":[],"from_bookmark":false,"from_webstore":true,"granted_permissions":{"api":["notifications"],"manifest_permissions":[]},"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13083842466347551","lastpingday":"13083836398399551","location":1,"manifest":{"app":{"launch":{"container":"tab","web_url":"https://mail.google.com/mail/ca"},"urls":["*://mail.google.com/mail/ca"]},"current_locale":"cs","default_locale":"en","description":"Rychlý e-mail s možností vyhledávání a menším množstvím spamu.","icons":{"128":"128.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCuGglK43iAz3J9BEYK/Mz6ZhloIMMDqQSAaf3vJt4eHbTbSDsu4WdQ9dQDRcKlg8nwQdePBt0C3PSUBtiSNSS37Z3qEGfS7LCju3h6pI1Yr9MQtxw+jUa7kXXIS09VV73pEFUT/F7c6Qe8L5ZxgAcBvXBh1Fie63qb02I9XQ/CQIDAQAB","manifest_version":2,"name":"Gmail","options_page":"https://mail.google.com/mail/ca/#settings","permissions":["notifications"],"update_url":"http://clients2.google.com/service/update2/crx","version":"8.1"},"page_ordinal":"n","path":"pjkljhegncpnkpknbcohdijeoejaedia\\8.1_0","preferences":{},"regular_only_preferences":{},"state":1,"was_installed_by_default":true,"was_installed_by_oem":false}}},"pinned_tabs":[],"protection":{"macs":{"browser":{"show_home_button":"995195657F7A9CEAF7712E57FEB38339A36920074BCD0273C832C7377C286DA8"},"default_search_provider":{"keyword":"43B0541EFF033077127E79713157062FB47ADAFD8F0688412D7B2A6FEFB4E089","name":"89FB3FAF3504D0A21BC7F699202F72ADC3985803BF6A3A37EAA4FB69B03764C0","search_url":"597967DDEE83DD8AA3CFEE1C590B2F78CE87CF9933FDDC73784DF90038B853BA"},"default_search_provider_data":{"template_url_data":"B23F58CAD169C615897A15A5EB2636EF3869306DEDABF0761041408E8EBE706D"},"extensions":{"settings":{"aapocclcgogkmnckokdopfmhonfmgoek":"AE44AE5A340C09281352C36D3F3AA0AAAE37869A63FD76C77D9307647968715E","ahfgeienlihckogmohjhadlkjgocpleb":"302A1D9B5A186C2BD147891EE9740DABA1D91165F54129534EA53D8D5BE3850C","aohghmighlieiainnegkcijnfilokake":"A43D4D751633FBD80E81041C4EAE73BA3F4E36A1A2C15D3E640EA1CB83CD284A","apdfllckaahabafndbhieahigkjlhalf":"FD7479E9B3304A60FF52698C1AFA5980F4748309B56515CC8F422C1146BA2BEC","bepbmhgboaologfdajaanbcjmnhjmhfn":"946EB6D7B1F12007BA2F1BE877CC76E38F9B4E594B723F66514C914BEC409F56","blpcfgokakmgnkcojhhkbfbldkacnbeo":"E5AF768A2BD847DFFC4884BEA9D12C4BA1847CBB54CB938F47DF8C84150B077A","coobgpohoikkiipiblmjeljniedjpjpf":"96C5E9D3DBD38ED7E78566B55E3F96ED1575B37F8D1C622A75586D820348C97C","eemcgdkfndhakfknompkggombfjjjeno":"D8AC7DEBF133058C9CEC5F17772C678F9BBCD4745CEBC9EDC52305AA22A724B6","ennkphjdgehloodpbhlhldgbnhmacadg":"127F2BE56AEC583B9D5ED1970C89BDF9D52111B0D42A2DF525E83FF2CC007C63","felcaaldnbdncclmgdcncolpebgiejap":"0F1A90071D727BBD3E9AFCE282D3F608CBF96F434BC67984917ABB29DBC26B8F","gfdkimpbcpahaombhbimeihdjnejgicl":"273EFF3485D9FC04D08D1232B193A82E854FAFCCC8245EEB90BD24664E3707E1","kmendfapggjehodndflmmgagdbamhnfd":"414679D4DD63CA7BF3004507C0C179E3B82D76BE7522DCAF550B8DEDB9CE9115","knebimhcckndhiglamoabbnifdkijidd":"EDCC843B0DB1ED49E1B59C4D3BBCF11FA9C0ACA1E89C812629193D1E6AE24EA6","mfehgcgbbipciphmccgaenjidiccnmng":"B4E1FD13E45497AD6F750587E880E1A0F7E2D8103946A39577266888F74CF945","mfffpogegjflfpflabcdkioaeobkgjik":"27F7B6C3CC67654A42829A22A82A0C1B97683E1734481E317C0A6EA02A0EB139","mgndgikekgjfcpckkfioiadnlibdjbkf":"F0544534F245AA58296926518B2E16BE84E672183549299A14DD9AC1A09BAFBC","mhjfbmdgcfjbbpaeojofohoefgiehjai":"24A65DCB92B545F54BED69822395AEF4503BA860C147C4D3FCE3BF4B1155BF7C","neajdppkdcdipfabeoofebfddakdcjhd":"BFBA6BFC9BF65649B727009E2751AE891D79699DEAD9F03EC0B8FF4710234F83","nkeimhogjdpnpccoofpliimaahmaaome":"A2CF965243F639C2245505413B07880438C84C088EDCACB16EC11C948AB39437","nmmhkkegccagdldgiimedpiccmgmieda":"B3546A72E05468BF796DC91D2EC8593355EDC37C35B09A85279A4DF1A3D32E29","pafkbggdmjlpgkdkcbjmhmfcdpncadgh":"BCC469568146F49F23755BBA1EF6427136ED68A65FA6B5703D48FEF8B63D7D7F","pjkljhegncpnkpknbcohdijeoejaedia":"AF27435AD6E30FDB4D2416EEF612D180E729FD36A7E6686391740FBF4B74E630"}},"google":{"services":{"account_id":"CA86560E10BD48E510218134D8D686535DADF8043BFCA88606E1CE58945BB9C6","last_username":"3B53D867E0DFCFD401D483EFB21363EA5B4DB254581077D5C10CB3CA0ABFD7AB","username":"A2FE665DC5FFC9B9268E30D8AF3C8E19EA71AE2ADD51ECA77505A9DF222BBC97"}},"homepage":"0822339600223698D8F3D2971DC44C37956C5B8DED5E928C961704A51F718ACB","homepage_is_newtabpage":"CE1854A580D187F692E2F64A8FA1EA44D9E19B72717FFBDEDFC45A0A0CBA97DA","pinned_tabs":"53FEB332993AA72E485AC85E4C2F1504FFF338D87C316B52EB018C734C6F26AB","prefs":{"preference_reset_time":"6A280226A65407BDAD9AA877C89D4045830A946109842F24F46052D102D56758"},"profile":{"reset_prompt_memento":"E9A14551BD3150C87BBC49E1F74F16E63A5177E9BEF1D2A421A3C448CA4D5498"},"safebrowsing":{"incidents_sent":"3CD3071F7D826982BFF6E4238B5FAB7E7CC65223355A2E64D2B7F8A33DD38984"},"search_provider_overrides":"C5CEA7DC15FB6C05EC15D52EF7636DFA5A3F02122527F3F2728C6EDB5FAD7D6D","session":{"restore_on_startup":"A18F85672C9EF06CD82A380D6C681E0E3D8F1F005C09E6240EFF012927AEFA06","startup_urls":"442A2DD659013C22BCB976763C2C76798B766B4BCCEE5E6EC7EB534AF34A7388"},"software_reporter":{"prompt_reason":"FEDF14EF647E7FEC6A74050300916A6E462DD439D48A4E3A69144CE306164413","prompt_seed":"04C696D337980E982FDD30AD330E40180D0021F91A0B876A1E3EEEA39B3FC4EB","prompt_version":"44FF51C6DDFB37ABFE07ADEDF869CC8383C4BF9538B37757E2B793B246D538E1"},"sync":{"remaining_rollback_tries":"01BB833C3FF33B68AA18FAC295A6A8342B83A6D91A1F1A937B2EE9E770DFD3AC"}},"super_mac":"CA533011B01C74361BC6AEB8A3C4098E032BA26D0E3AE032BD191C4A147C2BE9"},"session":{"restore_on_startup":4,"startup_urls":["https://www.seznam.cz/"]}}


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully

==== Empty IE Cache ======================

C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\IE\4JWFLH7J will be deleted at reboot
C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\IE\AFXT7VG5 will be deleted at reboot

==== Empty FireFox Cache ======================

C:\Users\Petr\AppData\Local\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================


==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Petr\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied
C:\RECYCLER successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\IE\4JWFLH7J" not found
"C:\Users\Petr\AppData\Local\Microsoft\Windows\INetCache\IE\AFXT7VG5" not found

==== EOF on 13.08.2015 at 16:48:56,66 ======================
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 13 srp 2015 17:16

Pičítač je rychlejší, to rozhodně. A problém, kvůli kterému jsem založil tohle vlákno, se od včerejška nevyskytl. To ale rozhodně neznamená, že se nevyskytne v budoucnu.

Trápí mě ale ještě jedna věc. Nemohu na ploše přesouvat ikony. Co jsem četl na netu, je to buď tím, že nové windejsi nejsou bez much, nebo nějakým virem. Virus asi můžeme vyloučit... Pokud by tě napadlo, co by to mohlo napravit, byl bych rád. A automaticky zarovnávat ikony a Zarovnat ikony k mřížce je odškrtnuté.

Ono vůbec po startu počítače dlouho trvá, než se ty ikony objeví. Používám Fences, ale tím to, myslím, nebude...
Ještě tohle - chvíli po startu a po tom, co se ikony objeví, jdou přesunout. Ale během pár vteřin se zase vrátí na své původní místo a už přesouvat nejdou.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:11:32, on 13.08.2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
C:\WINDOWS\system32\notepad.exe
C:\Windows\System32\RuntimeBroker.exe
C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG2015\avgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe
G:\Instalačky\Správa počítače\HijackThis.exe
C:\WINDOWS\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
O4 - HKLM\..\Run: [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
O4 - HKLM\..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2015\avgui.exe" /TRAYONLY
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O22 - SharedTaskScheduler: FencesShellExt - {1984DD45-52CF-49cd-AB77-18F378FEA264} - C:\Program Files\Stardock\Fences\FencesMenu.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2015\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: FreemakeVideoCapture - Ellora Assets Corp. - C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvvsvc.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe

--
End of file - 6476 bytes
Keybord not present. Press Enter to continue

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 13 srp 2015 19:26

Z Comoda používáš firewall? V AVG ho máš taky , 2 firewally je hloupost..

Nemá nějak zamknutou plochu? win 10 nemám , takže neporadím .

Ještě se na to kouknem:

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 14 srp 2015 08:52

Měl jsem firewall od Comodo, v AVG byl neaktivní. Včera jsem ho aktivoval v AVG a Comodo jsem odinstaloval.

S tou zamčenou plochou nevím, já jsem ji rozhodně nezamykal, ale jestli je, nebo není zamčená, to nemohu vyloučit... Ani nevím, kde se zamyká :-)

Zde je první část logu FRST.exe:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-08-2015
Ran by Petr (administrator) on INTEL (14-08-2015 08:44:39)
Running from C:\Users\Petr\Desktop
Loaded Profiles: Petr (Available Profiles: Petr)
Platform: Microsoft Windows 10 Home (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [P17RunE] => RunDll32 P17RunE.dll,RunDLLEntry
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-28] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3780520 2015-08-05] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\System32\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\Run: [OneDrive] => C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe [402632 2015-08-09] (Microsoft Corporation)
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-17] (Piriform Ltd)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-16] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-16] (Oracle Corporation)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0018-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.8.0/jinsta ... s-i586.cab
Tcpip\Parameters: [DhcpNameServer] 213.46.172.37 213.46.172.36
Tcpip\..\Interfaces\{c6846616-3e73-45d0-840e-dae156dada32}: [DhcpNameServer] 213.46.172.37 213.46.172.36

FireFox:
========
FF ProfilePath: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877
FF Homepage: https://www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-13] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll [2009-05-12] (DivX,Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-16] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-16] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-08-07] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-08-07] (NVIDIA Corporation)
FF Plugin: @pages.tvunetworks.com/WebPlayer -> C:\Program Files\TVUPlayer\npTVUAx.dll [2010-04-23] (TVU networks)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-16] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\searchplugins\thepiratebayorg.xml [2015-05-06]
FF SearchPlugin: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\searchplugins\wikipedia-ssl-de.xml [2015-05-06]
FF SearchPlugin: C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\searchplugins\wikipedia-ssl.xml [2015-05-06]
FF Extension: Český slovník pro kontrolu pravopisu (bez diakritiky) - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\cs2@dictionaries.addons.mozilla.org [2015-08-13]
FF Extension: Český slovník pro kontrolu pravopisu - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\cs@dictionaries.addons.mozilla.org [2015-05-15]
FF Extension: Memory Fox - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B} [2015-08-13]
FF Extension: Seznam lištička - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2015-08-13]
FF Extension: about:addons-memory - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\about-addons-memory@tn123.org.xpi [2015-08-13]
FF Extension: Classic Theme Restorer (Customize UI) - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi [2015-08-13]
FF Extension: Ghostery - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\firefox@ghostery.com.xpi [2015-08-13]
FF Extension: Restart My Fox - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\Restart-My-Fox@8pecxstudios.com.xpi [2015-08-13]
FF Extension: Save-To-Read - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\save2read@konstantin.plotnikov.xpi [2015-08-13]
FF Extension: Thumbnail Zoom Plus - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\thumbnailZoom@dadler.github.com.xpi [2015-08-13]
FF Extension: Flagfox - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2015-08-13]
FF Extension: NoScript - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2015-08-13]
FF Extension: Adblock Plus - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-08-13]
FF Extension: Tab Mix Plus - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2015-08-13]
FF Extension: Download Manager Tweak - C:\Users\Petr\AppData\Roaming\Mozilla\Firefox\Profiles\g82kcs7k.default-1430921114877\Extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2015-08-13]
FF HKLM\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2013-07-20]
FF HKLM\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2013-07-20]

Chrome:
=======
CHR Profile: C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-12]
CHR Extension: (Google Docs) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-12]
CHR Extension: (Google Drive) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-12]
CHR Extension: (YouTube) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-12]
CHR Extension: (Google Search) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-12]
CHR Extension: (Google Sheets) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-12]
CHR Extension: (Adblock Super) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\knebimhcckndhiglamoabbnifdkijidd [2015-08-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-21]
CHR Extension: (Gmail) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-12]
StartMenuInternet: ChromePlus - C:\Users\Petr\AppData\Roaming\ChromePlus\chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgfws; C:\Program Files\AVG\AVG2015\avgfws.exe [1560592 2015-08-05] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3633576 2015-08-05] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [335656 2015-08-05] (AVG Technologies CZ, s.r.o.)
R2 CoreMessagingRegistrar; C:\WINDOWS\system32\coremessaging.dll [588800 2015-08-09] (Microsoft Corporation)
S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2011-11-08] (Creative Labs) [File not signed]
S3 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [307200 2008-11-18] (Creative Technology Ltd) [File not signed]
S3 diagnosticshub.standardcollector.service; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [23040 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\WINDOWS\system32\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)
S3 Fabs; C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S3 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-12-03] (Freemake) [File not signed]
S3 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-12-03] (Ellora Assets Corp.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [921232 2015-07-28] (NVIDIA Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-07-02] (Malwarebytes Corporation)
R2 MSMQ; C:\WINDOWS\system32\mqsvc.exe [24576 2015-08-09] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-28] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4305040 2015-07-28] (NVIDIA Corporation)
R2 OneSyncSvc_Session2; C:\WINDOWS\system32\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc_Session2; C:\WINDOWS\system32\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 SensorDataService; C:\WINDOWS\System32\SensorDataService.exe [669696 2015-08-09] (Microsoft Corporation)
S4 ServiceLayer; C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe [632832 2011-03-21] (Nokia) [File not signed]
S3 UnistoreSvc_Session2; C:\WINDOWS\System32\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 UserDataSvc_Session2; C:\WINDOWS\system32\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 w3logsvc; C:\WINDOWS\system32\inetsrv\w3logsvc.dll [72192 2015-08-09] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [277760 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23264 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 Avgbootx; C:\WINDOWS\System32\DRIVERS\avgbootx.sys [19104 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiskx; C:\WINDOWS\System32\DRIVERS\avgdiskx.sys [132576 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\WINDOWS\system32\DRIVERS\avgfwd6x.sys [68032 2015-08-03] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\WINDOWS\System32\DRIVERS\avgidsdriverx.sys [250288 2015-07-28] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\WINDOWS\System32\DRIVERS\avgidshx.sys [190944 2015-05-12] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\WINDOWS\system32\DRIVERS\avgidsshimw8x.sys [31664 2015-07-23] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\WINDOWS\System32\DRIVERS\avgldx86.sys [207328 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\WINDOWS\System32\DRIVERS\avglogx.sys [290272 2015-07-11] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\WINDOWS\System32\DRIVERS\avgmfx86.sys [186800 2015-07-28] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\WINDOWS\System32\DRIVERS\avgrkx86.sys [35808 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpx; C:\WINDOWS\system32\DRIVERS\avgwfpx.sys [230848 2015-07-10] (AVG Technologies CZ, s.r.o.)
R1 BasicRender; C:\WINDOWS\System32\drivers\BasicRender.sys [30720 2015-07-10] (Microsoft Corporation)
S3 buttonconverter; C:\WINDOWS\System32\drivers\buttonconverter.sys [23552 2015-07-10] (Microsoft Corporation)
S3 CapImg; C:\WINDOWS\System32\drivers\capimg.sys [96768 2015-07-10] (Microsoft Corporation)
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [647888 2015-08-05] (COMODO)
R1 cmdhlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30400 2015-08-05] (COMODO)
R3 CompositeBus; C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_x86_a4832450a7024d49\CompositeBus.sys [31232 2015-07-10] (Microsoft Corporation)
R1 dtsoftbus01; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [243128 2014-10-12] (Disc Soft Ltd)
S3 fcvsc; C:\WINDOWS\System32\drivers\fcvsc.sys [24064 2015-07-10] (Microsoft Corporation)
R1 FileCrypt; C:\WINDOWS\System32\drivers\filecrypt.sys [74240 2015-07-10] (Microsoft Corporation)
S3 genericusbfn; C:\WINDOWS\System32\drivers\genericusbfn.sys [17408 2015-07-10] (Microsoft Corporation)
S3 GPIO; C:\WINDOWS\System32\drivers\iaiogpio.sys [22016 2015-07-10] (Intel Corporation)
R1 GpuEnergyDrv; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [7680 2015-07-10] (Microsoft Corporation)
S3 hidinterrupt; C:\WINDOWS\System32\drivers\hidinterrupt.sys [37728 2015-07-10] (Microsoft Corporation)
R2 HWiNFO32; D:\Program Files\HWiNFO32\HWiNFO32.SYS [20216 2011-05-22] (REALiX(tm))
S3 IoQos; C:\WINDOWS\System32\drivers\ioqos.sys [23040 2015-07-10] (Microsoft Corporation)
S0 LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [88928 2015-07-10] (LSI Corporation)
S0 LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [83296 2015-07-10] (Avago Technologies)
S3 LVPr2Mon; C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys [25752 2009-10-07] ()
R3 LVUSBSta; C:\WINDOWS\System32\drivers\LVUSBSta.sys [41752 2008-07-26] (Logitech Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-07-02] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-07-02] (Malwarebytes Corporation)
S0 megasas; C:\WINDOWS\System32\drivers\megasas.sys [52064 2015-07-10] (Avago Technologies)
R2 MMCSS; C:\WINDOWS\system32\drivers\mmcss.sys [37376 2015-07-10] (Microsoft Corporation)
R3 MQAC; C:\WINDOWS\System32\drivers\mqac.sys [130048 2015-08-09] (Microsoft Corporation)
S3 netvsc; C:\WINDOWS\System32\drivers\netvsc.sys [80384 2015-07-10] (Microsoft Corporation)
R2 npf; C:\WINDOWS\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [18576 2015-07-24] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad32v.sys [42344 2015-07-15] (NVIDIA Corporation)
R3 P17; C:\WINDOWS\system32\drivers\P17.sys [1147392 2009-04-21] (Creative Technology Ltd.)
R3 pepifilter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [13848 2008-07-26] (Logitech Inc.)
S0 percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [51040 2015-07-10] (LSI Corporation)
S0 percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [51552 2015-07-10] (Avago Technologies)
R3 PID_PEPI; C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2570520 2008-07-26] (Logitech Inc.)
R3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [492032 2015-07-10] (Realtek )
R0 sfhlp02; C:\WINDOWS\System32\drivers\sfhlp02.sys [6656 2005-05-16] (Protection Technology) [File not signed]
R2 storqosflt; C:\WINDOWS\System32\drivers\storqosflt.sys [52736 2015-07-10] (Microsoft Corporation)
S0 storufs; C:\WINDOWS\System32\drivers\storufs.sys [33632 2015-07-10] (Microsoft Corporation)
R3 swenum; C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_x86_b6707c73599dd1b6\swenum.sys [16224 2015-07-10] (Microsoft Corporation)
S3 tap0901; C:\WINDOWS\System32\DRIVERS\tap0901.sys [31360 2013-02-08] (The OpenVPN Project)
S3 UcmCx0101; C:\WINDOWS\System32\Drivers\UcmCx.sys [45056 2015-07-10] (Microsoft Corporation)
S3 UcmUcsi; C:\WINDOWS\System32\drivers\UcmUcsi.sys [32768 2015-08-09] (Microsoft Corporation)
S3 UdeCx; C:\WINDOWS\System32\drivers\udecx.sys [31744 2015-07-10] ()
S3 Ufx01000; C:\WINDOWS\System32\drivers\ufx01000.sys [190816 2015-07-10] (Microsoft Corporation)
S3 UfxChipidea; C:\WINDOWS\System32\drivers\UfxChipidea.sys [73568 2015-07-10] (Microsoft Corporation)
S3 ufxsynopsys; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [100704 2015-07-10] (Microsoft Corporation)
S3 UrsChipidea; C:\WINDOWS\System32\drivers\urschipidea.sys [21856 2015-07-10] (Microsoft Corporation)
S3 UrsCx01000; C:\WINDOWS\System32\drivers\urscx01000.sys [42848 2015-07-10] (Microsoft Corporation)
S3 UrsSynopsys; C:\WINDOWS\System32\drivers\urssynopsys.sys [21856 2015-07-10] (Microsoft Corporation)
S3 vhf; C:\WINDOWS\System32\drivers\vhf.sys [24064 2015-07-10] (Microsoft Corporation)
S3 wdiwifi; C:\WINDOWS\System32\DRIVERS\wdiwifi.sys [488960 2015-08-06] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [97632 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRT; C:\WINDOWS\System32\drivers\WindowsTrustedRT.sys [86552 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRTProxy; C:\WINDOWS\System32\drivers\WindowsTrustedRTProxy.sys [15384 2015-07-10] (Microsoft Corporation)
R0 Wof; C:\WINDOWS\system32\Drivers\Wof.sys [173408 2015-08-06] (Microsoft Corporation)
S3 xboxgip; C:\WINDOWS\System32\drivers\xboxgip.sys [186368 2015-07-10] (Microsoft Corporation)
S3 xinputhid; C:\WINDOWS\System32\drivers\xinputhid.sys [18432 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVC: NetSetupSvc -> C:\Windows\System32\NetSetupSvc.dll (Microsoft Corporation)
NETSVC: DcpSvc -> C:\Windows\system32\dcpsvc.dll (Microsoft Corporation)
NETSVC: UserManager -> C:\Windows\System32\usermgr.dll (Microsoft Corporation)
NETSVC: dosvc -> C:\Windows\system32\dosvc.dll (Microsoft Corporation)
NETSVC: dmwappushservice -> C:\Windows\system32\dmwappushsvc.dll (Microsoft Corporation)
NETSVC: XboxNetApiSvc -> C:\Windows\system32\XboxNetApiSvc.dll (Microsoft Corporation)
NETSVC: UsoSvc -> C:\Windows\system32\usocore.dll (Microsoft Corporation)
NETSVC: RetailDemo -> C:\Windows\system32\RDXService.dll (Microsoft Corporation)
NETSVC: DmEnrollmentSvc -> C:\Windows\system32\Windows.Internal.Management.dll (Microsoft Corporation)
NETSVC: XblAuthManager -> C:\Windows\System32\XblAuthManager.dll (Microsoft Corporation)
NETSVC: XblGameSave -> C:\Windows\System32\XblGameSave.dll (Microsoft Corporation)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-14 08:44 - 2015-08-14 08:45 - 00025771 _____ C:\Users\Petr\Desktop\FRST.txt
2015-08-14 08:44 - 2015-08-14 08:44 - 00000000 ____D C:\FRST
2015-08-14 08:40 - 2015-08-14 08:44 - 01678336 _____ (Farbar) C:\Users\Petr\Desktop\FRST.exe
2015-08-14 08:23 - 2015-08-14 08:23 - 00016148 _____ C:\WINDOWS\system32\INTEL_Petr_HistoryPrediction.bin
2015-08-13 17:03 - 2015-08-14 08:33 - 00000000 ____D C:\Users\Petr\AppData\Local\CrashDumps
2015-08-13 17:01 - 2015-08-13 17:01 - 00002160 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2015-08-13 17:01 - 2015-08-07 06:41 - 00573232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvStreaming.exe
2015-08-13 16:59 - 2015-08-13 17:01 - 00000000 ____D C:\WINDOWS\LastGood
2015-08-13 16:57 - 2015-08-13 17:01 - 00000039 _____ C:\WINDOWS\setupact.log
2015-08-13 16:57 - 2015-08-13 16:58 - 00000000 ____D C:\Users\Petr\AppData\Local\Adobe
2015-08-13 16:57 - 2015-08-13 16:57 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-13 16:57 - 2015-08-07 12:23 - 37819000 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 18564912 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv32.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 13663232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 12186176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 02104440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 01049904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco3235560.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 01000088 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshim.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00985208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00931960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00912688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco3235560.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00632848 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00461136 _____ C:\WINDOWS\system32\nvmcumd.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00364336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00339576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00316120 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00155976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinit.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim32.dll
2015-08-13 16:57 - 2015-08-07 12:23 - 00037208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap32.dll
2015-08-13 16:44 - 2015-08-13 16:26 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2015-08-13 16:27 - 2015-08-13 16:48 - 00016334 _____ C:\zoek-results.log
2015-08-13 16:26 - 2015-08-13 16:42 - 00000000 ____D C:\zoek_backup
2015-08-13 16:24 - 2015-08-13 16:24 - 00012914 _____ C:\Users\Petr\Desktop\rogue2.txt
2015-08-13 15:49 - 2015-08-13 16:26 - 01308672 _____ C:\Users\Petr\Desktop\zoek.exe
2015-08-13 12:23 - 2015-08-05 02:32 - 00007884 _____ C:\WINDOWS\system32\Drivers\cmdguard.cat
2015-08-13 12:23 - 2015-08-05 02:32 - 00007471 _____ C:\WINDOWS\system32\Drivers\inspect.cat
2015-08-13 12:23 - 2015-08-05 02:32 - 00007467 _____ C:\WINDOWS\system32\Drivers\cmdhlp.cat
2015-08-13 10:28 - 2015-08-13 16:48 - 00001166 _____ C:\WINDOWS\PFRO.log
2015-08-13 10:24 - 2015-08-13 10:53 - 01791580 _____ (Malwarebytes Corporation) C:\Users\Petr\Desktop\JRT.exe
2015-08-13 10:24 - 2015-08-13 10:32 - 18723912 _____ C:\Users\Petr\Desktop\RogueKiller.exe
2015-08-13 07:31 - 2015-08-13 07:38 - 00002003 _____ C:\Users\Petr\Desktop\CrystalDiskInfo.lnk
2015-08-13 07:31 - 2015-08-13 07:32 - 00000000 ____D C:\Program Files\CrystalDiskInfo
2015-08-12 21:58 - 2015-08-13 10:27 - 00000000 ____D C:\AdwCleaner
2015-08-12 21:50 - 2015-08-12 21:58 - 02248704 _____ C:\Users\Petr\Desktop\AdwCleaner.exe
2015-08-12 20:34 - 2015-08-14 08:26 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-12 12:23 - 2015-08-12 12:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-12 12:12 - 2015-08-12 12:12 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-08-12 09:00 - 2015-08-12 10:30 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-08-12 08:48 - 2015-08-08 09:01 - 06264160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 08:48 - 2015-08-08 08:59 - 01535032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 08:48 - 2015-08-08 08:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 08:48 - 2015-08-08 08:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 08:48 - 2015-08-08 08:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 08:48 - 2015-08-08 08:00 - 01391104 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 08:48 - 2015-08-08 07:58 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 08:48 - 2015-08-08 07:58 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-12 08:48 - 2015-08-06 04:50 - 00197472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 08:48 - 2015-08-06 04:50 - 00173408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 08:48 - 2015-08-06 04:03 - 18805248 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-12 08:48 - 2015-08-06 04:01 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 08:48 - 2015-08-05 06:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 08:48 - 2015-08-05 05:43 - 01916416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-12 08:48 - 2015-08-05 05:40 - 00995840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 08:48 - 2015-08-05 05:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 08:48 - 2015-08-05 05:32 - 02987008 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-12 08:48 - 2015-08-05 05:32 - 01134592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 08:48 - 2015-08-04 05:50 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-12 08:48 - 2015-08-04 05:50 - 00085344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 08:48 - 2015-08-04 05:10 - 13025792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 08:48 - 2015-08-04 05:10 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 08:48 - 2015-08-04 04:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 08:48 - 2015-08-03 04:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 08:48 - 2015-08-03 03:57 - 01709920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 08:48 - 2015-08-03 03:57 - 00503600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 08:48 - 2015-08-03 03:57 - 00436064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 08:48 - 2015-08-03 03:57 - 00415072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 08:48 - 2015-08-03 03:57 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 08:48 - 2015-08-03 03:57 - 00042904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 08:48 - 2015-08-03 03:57 - 00036704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 08:48 - 2015-08-03 03:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 08:48 - 2015-08-03 03:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-12 08:48 - 2015-08-03 03:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 08:48 - 2015-08-03 03:18 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 08:48 - 2015-08-03 03:18 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 08:48 - 2015-08-03 03:13 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 08:48 - 2015-08-03 03:13 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 08:48 - 2015-08-03 03:12 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-12 08:48 - 2015-08-03 03:12 - 01823232 _____ C:\WINDOWS\system32\InputService.dll
2015-08-12 08:48 - 2015-08-03 03:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 08:48 - 2015-08-03 03:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 08:48 - 2015-08-03 03:11 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 08:48 - 2015-08-03 03:11 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 08:48 - 2015-08-03 03:11 - 00200704 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-12 08:48 - 2015-08-03 03:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 08:48 - 2015-08-03 03:10 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 08:48 - 2015-08-03 03:06 - 03025408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 08:48 - 2015-08-03 03:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 08:48 - 2015-08-03 03:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 08:48 - 2015-08-03 03:06 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 08:48 - 2015-08-03 03:05 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 08:48 - 2015-08-03 03:03 - 00719360 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-12 08:48 - 2015-08-03 03:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 08:48 - 2015-08-03 03:03 - 00445952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 08:48 - 2015-08-03 03:03 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 08:48 - 2015-08-03 03:02 - 01917440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-12 08:48 - 2015-08-03 03:02 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 08:48 - 2015-08-03 03:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 08:48 - 2015-08-03 03:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 08:48 - 2015-08-03 03:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 08:48 - 2015-08-03 03:00 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-12 08:48 - 2015-08-03 02:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 08:48 - 2015-08-03 02:57 - 01499136 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-10 13:41 - 2015-08-10 13:41 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-08-10 12:14 - 2015-08-10 12:16 - 00000000 ____D C:\Users\Petr\AppData\Local\MicrosoftEdge
2015-08-09 20:24 - 2015-07-30 06:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-08-09 20:24 - 2015-07-30 06:26 - 01341920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-08-09 20:24 - 2015-07-30 06:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-09 20:24 - 2015-07-30 06:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-08-09 20:24 - 2015-07-30 06:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 01769056 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-08-09 20:24 - 2015-07-30 06:23 - 01808224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-08-09 20:24 - 2015-07-30 06:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-08-09 20:24 - 2015-07-30 06:22 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-08-09 20:24 - 2015-07-30 06:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-08-09 20:24 - 2015-07-30 06:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-09 20:24 - 2015-07-30 06:09 - 00193888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-08-09 20:24 - 2015-07-30 05:47 - 01181536 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-09 20:24 - 2015-07-30 05:24 - 00196096 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-08-09 20:24 - 2015-07-30 05:24 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-08-09 20:24 - 2015-07-30 05:22 - 00371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-08-09 20:24 - 2015-07-30 05:21 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-09 20:24 - 2015-07-30 05:21 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-08-09 20:24 - 2015-07-30 05:21 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-08-09 20:24 - 2015-07-30 05:17 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-08-09 20:24 - 2015-07-30 05:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-08-09 20:24 - 2015-07-30 05:12 - 00675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-09 20:24 - 2015-07-30 05:12 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-08-09 20:24 - 2015-07-30 05:12 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-08-09 20:24 - 2015-07-30 05:10 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-09 20:24 - 2015-07-30 05:10 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 14 srp 2015 08:52

A zde je druhá část:

2015-08-09 20:24 - 2015-07-30 05:08 - 00484864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-09 20:24 - 2015-07-30 05:08 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-08-09 20:24 - 2015-07-30 05:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-08-09 20:24 - 2015-07-30 05:07 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-08-09 20:24 - 2015-07-30 05:06 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-09 20:24 - 2015-07-30 05:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-08-09 20:24 - 2015-07-30 05:06 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-08-09 20:24 - 2015-07-30 05:06 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-08-09 20:24 - 2015-07-30 05:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-08-09 20:24 - 2015-07-30 05:06 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-08-09 20:24 - 2015-07-30 05:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-08-09 20:24 - 2015-07-30 05:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-08-09 20:24 - 2015-07-30 05:04 - 00741376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-08-09 20:24 - 2015-07-30 05:04 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-08-09 20:24 - 2015-07-30 05:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-08-09 20:24 - 2015-07-30 05:03 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-08-09 20:24 - 2015-07-30 05:01 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-08-09 20:24 - 2015-07-30 05:00 - 01125888 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-08-09 20:24 - 2015-07-30 04:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-08-09 20:24 - 2015-07-30 04:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-08-09 13:43 - 2015-08-11 09:33 - 00000000 ___DC C:\WINDOWS\Panther
2015-08-09 13:40 - 2015-08-09 13:40 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00918880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-09 13:40 - 2015-08-09 13:40 - 00916800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00850784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-08-09 13:40 - 2015-08-09 13:40 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00729088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00301056 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00000000 ____D C:\Windows.old
2015-08-09 13:39 - 2015-08-09 13:39 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 04047288 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 02878000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01829376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01395568 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01275392 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01153536 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-08-09 13:39 - 2015-08-09 13:39 - 00987072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00923648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00920576 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00902320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00868752 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-08-09 13:39 - 2015-08-09 13:39 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00751520 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00548616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00520640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00506200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00469856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00442720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00369504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00351072 _____ (Microsoft Corporation) C:\WINDOWS\system32\halmacpi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00351072 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00284672 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00283136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00257888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00242264 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00191144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00054112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00037376 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-09 13:39 - 2015-08-09 13:39 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-08-09 13:39 - 2015-08-09 13:39 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-08-09 13:39 - 2015-08-09 13:39 - 00025088 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-08-09 13:37 - 2015-08-09 13:37 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\WINDOWS\system32\XPSViewer
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\Program Files\MSBuild
2015-08-09 13:31 - 2015-08-09 13:31 - 00000000 ____D C:\inetpub
2015-08-09 13:30 - 2015-05-29 22:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-08-09 13:30 - 2015-05-29 22:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-09 13:30 - 2015-05-29 22:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-08-09 13:22 - 2015-08-13 15:50 - 00000000 ___RD C:\Users\Petr\OneDrive
2015-08-09 13:22 - 2015-08-09 13:27 - 00000000 ____D C:\Users\Petr\AppData\Local\Comms
2015-08-09 13:22 - 2015-08-09 13:23 - 00002398 _____ C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-09 13:20 - 2015-08-09 13:20 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-09 13:18 - 2015-08-09 13:18 - 00001055 _____ C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volitelné funkce.lnk
2015-08-09 13:18 - 2015-07-09 20:39 - 04847104 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-08-09 13:18 - 2015-07-09 20:36 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-08-09 13:18 - 2015-07-09 20:36 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-08-09 13:17 - 2015-08-09 13:17 - 00000000 ____D C:\Users\Petr\AppData\Local\Publishers
2015-08-09 13:16 - 2015-08-09 13:16 - 00000000 ____D C:\Users\Petr\AppData\Local\TileDataLayer
2015-08-09 13:15 - 2015-08-09 13:15 - 00000020 ___SH C:\Users\Petr\ntuser.ini
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Šablony
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Poslední
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Okolní síť
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Dokumenty
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\Data aplikací
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2015-08-09 13:14 - 2015-08-09 13:14 - 00000000 __SHD C:\Recovery
2015-08-09 13:12 - 2015-08-09 13:12 - 00021496 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-08-09 13:09 - 2015-08-09 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-09 13:00 - 2015-08-09 13:00 - 00001544 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-09 13:00 - 2015-08-09 13:00 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2015-08-09 13:00 - 2015-08-09 13:00 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-08-09 13:00 - 2015-08-09 13:00 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2015-08-09 13:00 - 2015-08-09 13:00 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-08-09 12:55 - 2015-08-09 12:55 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-08-09 12:52 - 2015-08-12 20:33 - 00000000 ____D C:\Users\Petr
2015-08-09 12:52 - 2015-08-09 13:16 - 00000000 ___RD C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Šablony
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Soubory cookie
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Poslední
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Okolní tiskárny
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Okolní síť
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Nabídka Start
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Dokumenty
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Documents\Obrázky
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Documents\Hudba
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Documents\Filmy
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\Data aplikací
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-09 12:52 - 2015-08-09 12:52 - 00000000 _SHDL C:\Users\Petr\AppData\Local\Data aplikací
2015-08-09 12:52 - 2015-07-10 10:28 - 00000000 __RSD C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-09 12:52 - 2015-07-10 10:28 - 00000000 ___RD C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-09 12:52 - 2015-07-10 10:28 - 00000000 ___RD C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-09 12:52 - 2015-07-10 10:28 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-09 12:49 - 2015-08-13 16:55 - 02011214 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-09 12:47 - 2015-08-13 17:01 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-09 12:47 - 2015-08-13 17:01 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-09 12:47 - 2015-08-09 12:55 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-08-09 12:47 - 2015-08-07 06:26 - 04390520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-08-09 12:47 - 2015-08-07 06:26 - 03020080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc.dll
2015-08-09 12:47 - 2015-08-07 06:26 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-08-09 12:47 - 2015-08-07 06:26 - 00670840 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-08-09 12:47 - 2015-08-07 06:26 - 00374904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-08-09 12:47 - 2015-08-07 06:26 - 00061560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-08-09 12:47 - 2015-08-03 15:07 - 05133709 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-08-09 12:46 - 2015-08-09 13:50 - 00005214 _____ C:\WINDOWS\system32\lvcoinst.log
2015-08-09 12:46 - 2015-08-09 12:55 - 00000000 ____D C:\Program Files\Common Files\logishrd
2015-08-09 12:45 - 2015-08-09 12:45 - 00021951 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-08-09 12:14 - 2015-08-09 13:13 - 00010449 _____ C:\WINDOWS\diagerr.xml
2015-08-09 12:14 - 2015-08-09 13:13 - 00009528 _____ C:\WINDOWS\diagwrn.xml
2015-08-07 09:28 - 2015-08-05 02:31 - 00108144 _____ (COMODO) C:\WINDOWS\system32\Drivers\inspect.sys
2015-08-03 09:32 - 2015-08-09 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-08-03 07:49 - 2015-08-03 07:49 - 00000000 ____D C:\Users\Petr\AppData\Local\MFAData
2015-07-31 12:26 - 2015-07-31 12:27 - 00000000 ____D C:\Users\Petr\Documents\MAGIX Speed
2015-07-31 12:26 - 2015-07-31 12:26 - 00000000 ____D C:\Users\Petr\Documents\MAGIX Speed projects
2015-07-29 21:24 - 2015-08-13 17:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-07-29 08:10 - 2015-07-29 08:10 - 00000161 _____ C:\Delme.bat
2015-07-28 11:02 - 2015-07-28 11:02 - 00250288 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdriverx.sys
2015-07-28 11:02 - 2015-07-28 11:02 - 00186800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgmfx86.sys
2015-07-27 09:56 - 2015-07-29 08:10 - 00000000 ____D C:\Program Files\Kralovna jezer
2015-07-23 18:57 - 2015-07-23 21:16 - 00000000 ____D C:\ProgramData\RogueKiller
2015-07-23 16:44 - 2015-07-23 16:44 - 00031664 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsshimw8x.sys
2015-07-23 06:46 - 2015-08-11 21:52 - 09409664 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-07-23 06:46 - 2015-08-07 12:23 - 15328488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2um.dll
2015-07-23 06:46 - 2015-08-07 12:23 - 12609072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dum.dll
2015-07-23 06:46 - 2015-08-07 12:23 - 03060040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi.dll
2015-07-23 06:46 - 2015-08-07 12:23 - 00028267 _____ C:\WINDOWS\system32\nvinfo.pb
2015-07-23 06:46 - 2015-07-23 06:46 - 15754192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\SETC243.tmp
2015-07-23 06:46 - 2015-07-23 06:46 - 12973680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\SETA655.tmp
2015-07-23 06:46 - 2015-07-23 06:46 - 09237136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\SET7B8F.tmp
2015-07-23 06:46 - 2015-07-23 06:46 - 02963024 _____ (NVIDIA Corporation) C:\WINDOWS\system32\SET82CB.tmp
2015-07-23 06:46 - 2015-07-23 06:46 - 01049416 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco3235362.dll
2015-07-23 06:46 - 2015-07-23 06:46 - 00912528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco3235362.dll
2015-07-20 22:26 - 2015-07-20 22:37 - 00000070 _____ C:\Users\Petr\turtle.layout.hiscores
2015-07-17 14:15 - 2015-07-17 14:15 - 00000000 ____D C:\Users\Petr\AppData\Local\CEF
2015-07-15 23:40 - 2015-07-15 23:40 - 00065896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap32v.dll
2015-07-15 23:40 - 2015-07-15 23:40 - 00042344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad32v.sys
2015-07-15 18:57 - 2015-07-09 19:42 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-07-15 18:57 - 2015-06-09 21:35 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\RdpGroupPolicyExtension.dll
2015-07-15 18:54 - 2015-07-15 18:54 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmlmedia.dll
2015-07-15 18:54 - 2015-07-15 18:54 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MsSpellCheckingFacility.exe
2015-07-15 11:19 - 2015-07-15 11:19 - 00000000 ____D C:\Users\Petr\AppData\Local\Electronic Arts

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-14 08:29 - 2015-05-10 13:53 - 00000000 ____D C:\ProgramData\MFAData
2015-08-14 08:24 - 2015-05-27 10:05 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-14 08:24 - 2015-03-24 01:42 - 00000000 ____D C:\ProgramData\Comodo
2015-08-14 08:23 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-13 17:16 - 2015-05-27 10:05 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-13 16:57 - 2015-05-24 10:03 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-13 16:48 - 2015-07-10 11:55 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-13 16:47 - 2015-07-10 08:59 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-08-13 16:08 - 2014-06-08 21:01 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-08-13 15:46 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\Microsoft.NET
2015-08-13 10:36 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-08-12 22:23 - 2014-07-07 14:51 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-08-12 20:32 - 2015-07-10 11:53 - 02237592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 20:28 - 2015-07-10 10:28 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 20:28 - 2015-07-10 10:28 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 20:28 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-12 20:27 - 2011-11-11 09:40 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-12 12:24 - 2011-11-09 12:50 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-12 12:21 - 2015-07-10 10:20 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-12 12:20 - 2013-08-14 23:46 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 12:13 - 2011-11-16 06:59 - 129304528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-08-12 11:07 - 2012-02-02 14:49 - 00000000 ____D C:\Users\Petr\AppData\Roaming\ChromePlus
2015-08-12 10:39 - 2012-10-01 20:00 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Stardock
2015-08-12 10:30 - 2014-02-06 19:57 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2015-08-12 08:47 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-11 09:26 - 2011-12-02 16:16 - 00001042 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-08-11 09:26 - 2011-11-09 11:15 - 00000000 ____D C:\Program Files\CCleaner
2015-08-10 12:26 - 2011-11-16 06:48 - 00000000 ____D C:\Users\Petr\TapinRadio
2015-08-10 12:08 - 2015-01-16 08:07 - 00000000 ____D C:\Users\Petr\AppData\Roaming\QuickScan
2015-08-10 12:08 - 2014-05-13 20:00 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Skype
2015-08-10 12:08 - 2014-04-25 13:05 - 00000000 ____D C:\Users\Petr\AppData\Roaming\avidemux
2015-08-10 12:08 - 2011-11-09 12:50 - 00000000 ____D C:\Users\Petr\AppData\Local\Microsoft Help
2015-08-10 12:07 - 2015-07-10 15:47 - 00000000 ___HD C:\$Windows.~BT
2015-08-10 11:46 - 2014-02-07 10:33 - 00000000 ____D C:\ProgramData\AVG
2015-08-10 11:09 - 2015-05-10 13:56 - 00000000 ____D C:\Program Files\AVG
2015-08-10 09:19 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\Provisioning
2015-08-10 08:05 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\AppCompat
2015-08-09 19:35 - 2015-07-10 08:59 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-09 15:35 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\restore
2015-08-09 15:35 - 2015-07-10 10:24 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dplayx.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpwsockx.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpmodemx.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2015-08-09 15:35 - 2015-07-10 10:24 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dplaysvr.exe
2015-08-09 15:35 - 2015-07-10 10:24 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2015-08-09 15:35 - 2015-07-10 10:24 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2015-08-09 15:30 - 2015-07-11 09:52 - 00000000 ____D C:\Users\Petr\AppData\Local\Avg2015
2015-08-09 13:43 - 2015-07-10 10:28 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-08-09 13:40 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-08-09 13:31 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-08-09 13:31 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-08-09 13:31 - 2015-07-10 10:25 - 01014272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-08-09 13:31 - 2015-07-10 10:25 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-08-09 13:31 - 2015-07-10 10:25 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-08-09 13:31 - 2015-07-10 10:25 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-08-09 13:31 - 2015-07-10 10:25 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-08-09 13:31 - 2015-07-10 10:25 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-08-09 13:31 - 2015-07-10 10:25 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-08-09 13:31 - 2015-07-10 10:25 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-08-09 13:31 - 2015-07-10 10:25 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-08-09 13:31 - 2015-07-10 10:25 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-08-09 13:30 - 2015-07-10 10:25 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-08-09 13:30 - 2015-07-10 10:25 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-08-09 13:30 - 2015-07-10 10:25 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-08-09 13:19 - 2015-07-10 15:19 - 00000000 ____D C:\WINDOWS\OCR
2015-08-09 13:17 - 2015-07-10 10:28 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-08-09 13:17 - 2015-07-10 10:28 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-08-09 13:17 - 2015-07-10 10:28 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-08-09 13:17 - 2015-07-10 10:28 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-08-09 13:16 - 2015-07-10 10:28 - 00000000 ___RD C:\Users\Public
2015-08-09 13:16 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\rescache
2015-08-09 13:14 - 2015-07-10 10:28 - 00000000 ____D C:\Program Files\Windows NT
2015-08-09 13:14 - 2015-07-10 08:59 - 00000000 __RHD C:\Users\Default
2015-08-09 13:13 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\Registration
2015-08-09 13:13 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\Globalization
2015-08-09 13:12 - 2015-07-10 10:28 - 00000000 __RSD C:\WINDOWS\Media
2015-08-09 13:12 - 2015-07-10 10:28 - 00000000 __RHD C:\Users\Public\Libraries
2015-08-09 13:12 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\LogFiles
2015-08-09 13:09 - 2015-07-10 10:28 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-08-09 13:02 - 2015-07-10 15:22 - 00000000 ____D C:\WINDOWS\ShellNew
2015-08-09 13:02 - 2015-04-24 11:09 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Thumbnail me 3.0
2015-08-09 13:02 - 2014-09-12 21:46 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2015-08-09 13:02 - 2014-04-16 19:28 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\8th Wonder Software Designs
2015-08-09 13:02 - 2014-01-28 21:13 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2015-08-09 13:02 - 2012-09-19 22:33 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\David Roško Usoft
2015-08-09 13:02 - 2012-02-02 14:49 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ChromePlus
2015-08-09 13:02 - 2011-12-27 19:29 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DOSBox-0.72
2015-08-09 13:02 - 2011-12-18 20:46 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-09 13:02 - 2011-11-08 16:13 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2015-08-09 13:00 - 2009-07-14 04:37 - 00000000 ____D C:\Users\Default.migrated
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\zh-TW
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\zh-CN
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\sv-SE
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\ru-RU
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\pt-PT
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\pt-BR
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\pl-PL
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\nl-NL
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\nb-NO
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\ko-KR
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\ja-JP
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\it-IT
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\IME
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\hu-HU
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\fr-FR
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\fi-FI
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\el-GR
2015-08-09 12:57 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\de-DE
2015-08-09 12:57 - 2014-07-30 19:12 - 00000000 ____D C:\WINDOWS\system32\xlive
2015-08-09 12:57 - 2013-02-20 22:04 - 00000000 ____D C:\WINDOWS\system32\Launchpad.libs
2015-08-09 12:57 - 2011-11-16 07:02 - 00000000 ____D C:\WINDOWS\system32\SPReview
2015-08-09 12:57 - 2011-11-16 07:01 - 00000000 ____D C:\WINDOWS\system32\EventProviders
2015-08-09 12:56 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\schemas
2015-08-09 12:56 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-08-09 12:56 - 2011-11-08 17:26 - 00000000 ____D C:\WINDOWS\system32\Adobe
2015-08-09 12:55 - 2015-07-10 10:28 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-08-09 12:55 - 2015-07-10 10:28 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-09 12:55 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\Help
2015-08-09 12:55 - 2015-07-10 10:28 - 00000000 ____D C:\Program Files\Microsoft.NET
2015-08-09 12:55 - 2015-07-10 10:28 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-09 12:55 - 2011-11-09 11:12 - 00000000 ____D C:\Program Files\Google
2015-08-09 12:55 - 2009-07-14 11:19 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-08-09 12:55 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Microsoft Games
2015-08-09 12:55 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\DVD Maker
2015-08-09 12:54 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-08-09 12:53 - 2014-09-28 12:19 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Murk
2015-08-09 12:53 - 2013-07-20 19:01 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-08-09 12:53 - 2012-10-02 13:15 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spacejock Software
2015-08-09 12:53 - 2012-01-15 15:18 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drazen's free games
2015-08-09 12:53 - 2011-11-20 12:05 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Terasoft
2015-08-09 12:46 - 2015-07-10 10:28 - 00000000 ____D C:\WINDOWS\twain_32
2015-08-09 12:22 - 2009-07-14 06:34 - 00022272 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-09 12:22 - 2009-07-14 06:34 - 00022272 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-09 11:50 - 2012-10-19 16:39 - 00000000 ____D C:\Users\Petr\AppData\Roaming\vlc
2015-08-08 17:38 - 2015-07-10 10:29 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2015-08-08 17:38 - 2015-07-10 10:29 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2015-08-07 12:23 - 2015-05-19 10:38 - 00105264 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-08-07 12:23 - 2015-04-16 19:03 - 00171352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda32v.sys
2015-08-07 12:23 - 2015-04-16 07:19 - 00921448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco3220103.dll
2015-08-05 09:36 - 2015-07-11 09:51 - 00000951 _____ C:\Users\Public\Desktop\AVG 2015.lnk
2015-08-05 02:31 - 2010-09-11 00:40 - 00647888 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdguard.sys
2015-08-05 02:31 - 2010-09-11 00:40 - 00030400 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmdhlp.sys
2015-08-05 02:31 - 2010-09-11 00:40 - 00017576 _____ (COMODO) C:\WINDOWS\system32\Drivers\cmderd.sys
2015-08-05 02:29 - 2011-11-11 17:11 - 00033496 _____ (COMODO) C:\WINDOWS\system32\cmdcsr.dll
2015-08-05 02:29 - 2010-09-11 00:41 - 00445472 _____ (COMODO) C:\WINDOWS\system32\guard32.dll
2015-08-05 02:27 - 2015-03-23 23:42 - 00288448 _____ (COMODO) C:\WINDOWS\system32\cmdvrt32.dll
2015-08-05 02:26 - 2015-03-23 23:42 - 00040640 _____ (COMODO) C:\WINDOWS\system32\cmdkbd32.dll
2015-08-03 12:15 - 2014-01-28 21:13 - 00000000 ____D C:\Users\Petr\AppData\Roaming\uTorrent
2015-08-03 09:32 - 2015-07-09 07:05 - 00068032 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgfwd6x.sys
2015-07-29 13:26 - 2011-12-18 15:32 - 00038400 _____ C:\Users\Petr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-27 10:38 - 2015-05-09 13:39 - 00127584 _____ C:\Users\Petr\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-26 22:16 - 2012-08-06 18:47 - 00000000 ____D C:\Users\Petr\Documents\My Games
2015-07-25 21:06 - 2011-11-09 12:09 - 00004493 _____ C:\Users\Petr\Desktop\Pulsa Denura.txt
2015-07-25 10:08 - 2011-11-08 16:09 - 00000000 ____D C:\Users\Petr\AppData\Local\VirtualStore
2015-07-24 13:49 - 2015-05-16 08:24 - 00000898 _____ C:\DelFix.txt
2015-07-24 06:21 - 2014-07-30 11:39 - 01316000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge.dll
2015-07-24 06:21 - 2014-07-21 17:29 - 01423304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap.dll
2015-07-19 13:02 - 2009-07-14 06:52 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-16 11:42 - 2011-11-08 16:29 - 00000000 ____D C:\Program Files\Java
2015-07-16 11:42 - 2011-11-08 16:29 - 00000000 ____D C:\Program Files\Common Files\Java
2015-07-16 11:41 - 2014-05-02 07:06 - 00096352 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll

==================== Files in the root of some directories =======

2012-08-06 18:24 - 2012-08-06 18:24 - 0138904 _____ () C:\Users\Petr\AppData\Roaming\PnkBstrK.sys
2013-10-18 11:35 - 2013-10-18 11:38 - 0030208 ___SH () C:\Users\Petr\AppData\Roaming\Thumbs.db
2012-07-28 17:27 - 2012-07-28 17:27 - 0021976 _____ () C:\Users\Petr\AppData\Roaming\UserTile.png
2011-12-18 15:32 - 2015-07-29 13:26 - 0038400 _____ () C:\Users\Petr\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-09 12:44

==================== End of log ============================
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 14 srp 2015 08:53

Zde je první část logu addition.exe:


Additional scan result of Farbar Recovery Scan Tool (x86) Version:13-08-2015
Ran by Petr (2015-08-14 08:45:55)
Running from C:\Users\Petr\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1382680524-3974183494-2248916863-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1382680524-3974183494-2248916863-503 - Limited - Disabled)
Guest (S-1-5-21-1382680524-3974183494-2248916863-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1382680524-3974183494-2248916863-1002 - Limited - Enabled)
Petr (S-1-5-21-1382680524-3974183494-2248916863-1001 - Administrator - Enabled) => C:\Users\Petr

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security 2015 (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Acrobat Reader DC - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 1.1.0.5790 - Adobe Systems Inc.)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (HKLM\...\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
Aktualizace NVIDIA 2.5.12.11 (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM\...\{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM\...\{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM\...\{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Apple Application Support (HKLM\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 1.3.12 (Unicode) (HKLM\...\Audacity 1.3 Beta (Unicode)_is1) (Version: - Audacity Team)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6125 - AVG Technologies CZ, s.r.o.)
AVG 2015 (Version: 15.0.4401 - AVG Technologies CZ, s.r.o.) Hidden
AVG 2015 (Version: 15.0.6125 - AVG Technologies CZ, s.r.o.) Hidden
Avidemux 2.6 (32-bit) (HKLM\...\Avidemux 2.6) (Version: 2.6.8.9045 - )
Balíček ovladače systému Windows - Nokia pccsmcfd (08/22/2008 7.0.0.0) (HKLM\...\504244733D18C8F63FF584AEB290E3904E791693) (Version: 08/22/2008 7.0.0.0 - Nokia)
BitTorrent (HKLM\...\BitTorrent) (Version: 7.5.0 - BitTorrent Inc.)
BitTorrent (HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\BitTorrent) (Version: 7.9.2.35704 - BitTorrent Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5000 - CDBurnerXP)
CloneSpy 2.63 (HKLM\...\CloneSpy) (Version: - CloneSpy)
COMODO Internet Security (HKLM\...\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}) (Version: 5.0.32580.1142 - COMODO Group Inc.)
Connect (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
Cookienator (HKLM\...\{BF307EDA-A176-4D83-9775-D337810CF7A7}) (Version: 2.6.41 - CodeFromThe70s.org)
Creative Audio Control Panel (HKLM\...\AudioCS) (Version: 2.56 - Creative Technology Limited)
Creative Software AutoUpdate (HKLM\...\Creative Software AutoUpdate) (Version: 1.40 - Creative Technology Limited)
Creative Sound Blaster Properties (HKLM\...\Creative Sound Blaster Properties) (Version: 1.02 - Creative Technology Limited)
CrystalDiskInfo 6.5.2 (HKLM\...\CrystalDiskInfo_is1) (Version: 6.5.2 - Crystal Dew World)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.03 - Piriform)
DivX Web Player (HKLM\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.5.0 - DivX,Inc.)
Ear Test 1.00 (HKLM\...\Ear Test_is1) (Version: - Johannes Wallroth)
EVEREST Home Edition v2.20 (HKLM\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
Fences (HKLM\...\Fences) (Version: - Stardock Corporation)
Fences (Version: 0.95 - Stardock Corporation) Hidden
File Shredder 2.5 (HKLM\...\File Shredder_is1) (Version: - WipeSoft)
Firebird SQL Server - MAGIX Edition (HKLM\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
FormatFactory 3.3.5.0 (HKLM\...\FormatFactory) (Version: 3.3.5.0 - Format Factory)
Freemake Video Converter verze 4.1.3 (HKLM\...\Freemake Video Converter_is1) (Version: 4.1.3 - Ellora Assets Corporation)
Freemake Video Downloader (HKLM\...\Freemake Video Downloader_is1) (Version: 3.7.1 - Ellora Assets Corporation)
Google Earth Plug-in (HKLM\...\{57BB4801-61C8-4E74-9672-2160728A461E}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.24.15 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
Grand Theft Auto Vice City (HKLM\...\{4B35F00C-E63D-40DC-9839-DF15A33EAC46}) (Version: 1.00.000 - )
ChromePlus (HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\ChromePlus) (Version: - Maple studio.)
Java 8 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Java DB 10.3.1.4 (HKLM\...\{CD49361E-3FE6-457E-90A1-9C59E29B5D02}) (Version: 10.3.1.4 - Sun Microsystems, Inc)
Java SE Development Kit 7 Update 15 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0170150}) (Version: 1.7.0.150 - Oracle)
Java SE Development Kit 8 Update 11 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0180110}) (Version: 8.0.110 - Oracle Corporation)
Java(TM) SE Development Kit 6 Update 5 (HKLM\...\{32A3A4F4-B792-11D6-A78A-00B0D0160050}) (Version: 1.6.0.50 - Sun Microsystems, Inc.)
K-Lite Codec Pack 6.0.4 (Basic) (HKLM\...\KLiteCodecPack_is1) (Version: 6.0.4 - )
kuler (Version: 2.0 - Adobe Systems Incorporated) Hidden
Logitech Vid HD (HKLM\...\Logitech Vid) (Version: 7.2 (7259) - Logitech Inc..)
Logitech Webcam Software (HKLM\...\{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}) (Version: 12.10.1113 - Logitech Inc.)
Magic FLAC to MP3 Converter 3.71 (HKLM\...\Magic FLAC to MP3 Converter_is1) (Version: - Magic Video)
MAGIX Burn routines (HKLM\...\{72945A77-20ED-4507-B267-4771EDE4EE58}) (Version: 11.0.0.233 - MAGIX AG)
MAGIX Content and Soundpools (HKLM\...\MAGIX_GlobalContent) (Version: 1.0.0.0 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Demo songs) (HKLM\...\MX.{B807FEBE-E253-4B7E-B23F-364873478065}) (Version: 1.0.0.0 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Demo songs) (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium (HKLM\...\MX.{088A4B09-8FB2-48D0-932A-7F90BE050543}) (Version: 20.0.2.35 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Introductory videos) (HKLM\...\MX.{4BA5297E-60A6-4F18-9AAC-25A878C4E38C}) (Version: 1.0.0.0 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Introductory videos) (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium (Synthesizer and effects) (HKLM\...\MX.{773A4DDC-3B52-42C7-8B7A-52369B9A390B}) (Version: 1.0.0.0 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Synthesizer and effects) (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium (Version: 20.0.2.35 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium (Visuals) (HKLM\...\MX.{A6A5590A-0FF9-4FD9-AD8D-17B5BCBE06F5}) (Version: 1.0.0.0 - MAGIX AG)
MAGIX Music Maker 2014 Premium (Visuals) (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium Soundpools (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Premium Update (Version: 20.0.3.45 - MAGIX AG) Hidden
MAGIX Music Maker 2014 Soundpools (Version: 1.0.0.0 - MAGIX AG) Hidden
MAGIX Speed burnR (MSI) (HKLM\...\MAGIX_{5C375A31-ED71-4CA0-91E0-8FA47E72D56D}) (Version: 7.0.1.27 - MAGIX AG)
MAGIX Speed burnR (MSI) (Version: 7.0.1.27 - MAGIX AG) Hidden
Malwarebytes Anti-Malware verze 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MediaInfo 0.7.73 (HKLM\...\MediaInfo) (Version: 0.7.73 - MediaArea.net)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft WorldWide Telescope (HKLM\...\{AC65361C-7AD1-4811-834A-6AEF497F9927}) (Version: 4.1.74 - Microsoft Research)
Mozilla Firefox 40.0 (x86 cs) (HKLM\...\Mozilla Firefox 40.0 (x86 cs)) (Version: 40.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 40.0.0.5697 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Music NFO Builder v1.20 (HKLM\...\Music NFO Builder_is1) (Version: - Pawel Piecuch)
NetBeans IDE 7.3 (HKLM\...\nbi-nb-base-7.3.0.0.201302132200) (Version: 7.3 - NetBeans.org)
Nokia Connectivity Cable Driver (HKLM\...\{25CFEF55-A945-41FC-86ED-76469F31DF37}) (Version: 7.1.41.0 - Nokia)
Nokia Music Player (HKLM\...\{4FCB1267-7380-4EBA-9A6C-69809C6E8227}) (Version: 2.5.11021 - Nokia Music Player)
Nokia_Multimedia_Common_Components_2_5 (HKLM\...\{25F61E72-AAA4-4607-95D2-1E5139C98FFB}) (Version: 2.7.69 - Nokia)
NVIDIA GeForce Experience 2.5.12.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 355.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 355.60 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 355.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 355.60 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenAL (HKLM\...\OpenAL) (Version: - )
Ovládací panel NVIDIA 355.60 (Version: 355.60 - NVIDIA Corporation) Hidden
Parom.TV player (HKLM\...\Parom.TV) (Version: - )
PatchBeam v1.10 (HKLM\...\PatchBeam_is1) (Version: 1.00 - ConeXware, Inc.)
PC Connectivity Solution (HKLM\...\{4B28C077-9958-45F1-8BB4-CBF90A69AD4E}) (Version: 11.4.15.0 - Nokia)
PDF Settings CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
PowerArchiver 2010 (HKLM\...\{789495D8-AF08-4B7C-9022-5F624F3CFB0B}) (Version: 11.71.03 - ConeXware, Inc.)
PSPad editor (HKLM\...\PSPad editor_is1) (Version: - Jan Fiala)
PunkBuster Services (HKLM\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Ramdisk (HKLM\...\Ramdisk) (Version: - )
Readon TV Movie Radio Player 7.6.0.0 (HKLM\...\{80074966-5231-428D-9AE7-B7D5D2DC3246}) (Version: 7.6.0 - Readon Technology)
Recuva (HKLM\...\Recuva) (Version: 1.42 - Piriform)
Scorpions WinCheater (HKLM\...\Scorpions WinCheater 2.07 (s databází 165)_is1) (Version: - )
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Sigil 0.7.4 (HKLM\...\Sigil_is1) (Version: - John Schember)
Skype™ 7.3 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
Smart Tests (HKLM\...\Smart Tests) (Version: 1.0.165.0 - Vitware)
Spotify (HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\Spotify) (Version: 1.0.6.80.g2a801a53 - Spotify AB)
SQLite3 manager 5.1 lite, release 280207 (HKLM\...\SQLite3 manager LITE_is1) (Version: - Ivan Sivak - SOFTWARE)
Stellarium 0.11.4 (HKLM\...\Stellarium_is1) (Version: 0.11.4 - Stellarium team)
Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TapinRadio 1.18 (HKLM\...\TapinRadio_is1) (Version: - TapinRadio)
Text-To-Speech-Runtime (HKLM\...\{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}) (Version: 1.0.0.0 - Magix Development GmbH)
Thumbnail me 3.0 (HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\Thumbnail me 3.0) (Version: - )
Total Commander (Remove or Repair) (HKLM\...\Totalcmd) (Version: - )
TS Dějepis (HKLM\...\TS Dějepis) (Version: - )
TS Dějepis (plná instalace) (HKLM\...\TS Dějepis (plná instalace)) (Version: - )
TVUPlayer 2.5.3.1 (HKLM\...\TVUPlayer) (Version: 2.5.3.1 - TVU networks)
Uc_heb a Hebrák 2.31 (HKLM\...\Uc_heb a Hebrák_is1) (Version: - )
Ucitilek (HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\9ead8755c3c1fd40) (Version: 1.0.7.128 - David Roško Usoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VC80CRTRedist - 8.0.50727.762 (Version: 1.0.0 - DivX, Inc) Hidden
VisiPics V1.30 (HKLM\...\VisiPics_is1) (Version: - Ozone)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
Visual Studio 2012 x86 Redistributables (HKLM\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vita 2 (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita 2 add-on content (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita Drum Engine (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita Electric Piano (Version: 1.0.2.0 - MAGIX AG) Hidden
Vita Jazz Drums (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita Pop Brass (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita Power Guitar (Version: 1.0.0.0 - MAGIX AG) Hidden
Vita Vintage Organ (Version: 1.0.1.0 - MAGIX AG) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
WinDjView 2.1 (HKLM\...\WinDjView) (Version: 2.1 - Andrew Zhezherun)
WinPcap 4.1.2 (HKLM\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
Word Manager (HKLM\...\Word Manager) (Version: 1.1.280.0 - Vitware.cz)
yBook (HKLM\...\yBook_is1) (Version: - Spacejock Software)
Yea Chess (HKLM\...\YeaChess) (Version: - )
Zoner Photo Studio 12 (HKLM\...\ZonerPhotoStudio12_CZ_is1) (Version: 12.0.1.7 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{5999E1EE-711E-48D2-9884-851A709F543D}\localserver32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{7B37E4E2-C62F-4914-9620-8FB5062718CC}\localserver32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{A3CA1CF4-5F3E-4AC0-91B9-0D3716E1EAC3}\localserver32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{AB807329-7324-431B-8B36-DBD581F56E0B}\localserver32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{BCAFD618-3FAE-4EFE-BF4E-4C43A7E1320B}\InprocServer32 -> C:\Program Files\Zoner\Photo Studio 12\Program\SHELLEXT.DLL (ZONER software)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncShell.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\FileSyncApi.dll (Microsoft Corporation)

==================== Restore Points =========================

09-08-2015 15:35:15 Instalační služba modulů systému Windows
12-08-2015 11:49:54 Adblock Plus for IE
13-08-2015 16:27:46 zoek.exe restore point

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-10-20 12:35 - 2015-08-13 16:28 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0339B993-0180-49D1-9BFF-22234124905E} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {07FF4B21-0D8E-4D65-A6C1-534AC4FEFC2F} - System32\Tasks\{7EE2D1FA-A015-4059-94A3-E8AE59D96553} => C:\Program Files\City Interactive\MOTORM4X Offroad Extreme\MOTORM4XOffroadExtremeCZ.exe
Task: {08C614E7-0E9E-4385-80A1-B57D741C85F0} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\WINDOWS\System32\LocationNotificationWindows.exe [2015-07-10] (Microsoft Corporation)
Task: {0B8B8675-BE25-4D7D-AAA3-50B1FA47252D} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\AikCertEnrollTask
Task: {0C72B578-D676-414D-9F9C-FF0B216A314F} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
Task: {0D9B836C-2254-4E5A-9F28-72AF04766658} - System32\Tasks\{5D5F9B0A-15E4-4884-9696-E6824DBEA113} => C:\Program Files\Skype\\Phone\Skype.exe [2015-03-25] (Skype Technologies S.A.)
Task: {13550F2C-A475-475F-AE32-F8D7682F8C40} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install => C:\WINDOWS\system32\usoclient.exe [2015-07-10] (Microsoft Corporation)
Task: {1D899708-86DF-4615-A9C5-DE4C0D3A3C7F} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {1E59CAD0-D49B-4553-88DE-227F411F5D57} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\WINDOWS\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)
Task: {201CF893-BC56-46DA-8598-6F75905C9028} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\Uninstallation
Task: {210B29B6-A68A-4580-AC06-855728389B03} - System32\Tasks\Microsoft\Windows\CertificateServicesClient\KeyPreGenTask
Task: {23D1E784-02DB-4882-8289-D6197915CA74} - System32\Tasks\{1AF97EA6-6EE2-41C6-9CBF-B7984A0F9C6E} => pcalua.exe -a "C:\!! Torrenty\Stažené soubory\Vtipy.exe" -d "C:\!! Torrenty\Stažené soubory"
Task: {274D1552-97F6-41D8-8970-F7AD48F26990} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {28BE504E-A6DC-4F2D-91DA-03C55102A8E3} - System32\Tasks\{2C11FBD0-8C6C-4F4A-9D6B-5A713790651D} => pcalua.exe -a "G:\Instalačky\Hry\!! Staré hry\MS DOS\grand-theft-auto-install.exe" -d "G:\Instalačky\Hry\!! Staré hry\MS DOS"
Task: {2E55AA51-E9B8-40B5-9EA6-0A24D15DDE63} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {3019FE5B-2B83-4DAD-977B-2EF6EDA8DCE5} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {36EF8C82-0B11-4D9F-8D02-07B59749910D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {37A8E238-7876-4DF4-8798-F244F8DC6342} - System32\Tasks\{644464D8-01F9-4966-A4E1-BF041B225D34} => pcalua.exe -a "G:\Instalačky\Hry\Medal of Honor Airborne (CZ)\redist\dxwebsetup9.29.1973.exe" -d "G:\Instalačky\Hry\Medal of Honor Airborne (CZ)\redist"
Task: {38E5D7F3-F358-41DE-91EC-1FC0CB695CBE} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {3C480DB5-9C57-4D02-A3C4-6737DD9DD027} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\WINDOWS\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)
Task: {3F628C45-4379-43B1-82E3-3D0AC5EF7C33} - System32\Tasks\Microsoft\Windows\Maps\MapsUpdateTask
Task: {489A34B7-9791-432B-A762-FEE4D0E9562E} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan => C:\WINDOWS\system32\usoclient.exe [2015-07-10] (Microsoft Corporation)
Task: {49C6F58F-98A3-4416-98C4-24BD457AC122} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {4C61D4C0-ADF1-48A4-91D6-C64A8CE35E79} - System32\Tasks\Microsoft\Windows\WCM\WiFiTask => C:\WINDOWS\System32\WiFiTask.exe [2015-07-10] (Microsoft Corporation)
Task: {4C7B56E3-0356-4A04-B96E-6F65F43BEE41} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Automatic App Update
Task: {51CB31CE-CEE7-4A17-88CC-78694367AEA0} - System32\Tasks\{6954F9FA-1B61-4D06-912E-4BA27D140ED1} => pcalua.exe -a "G:\Instalačky\Hry a programy\VirtuaNES\VirtuaNES.exe" -d "G:\Instalačky\Hry a programy\VirtuaNES"
Task: {51FDA8EC-D6D6-4C9F-B4CC-7BD1A023FEDC} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {536EC94E-1E69-43A9-A7EE-1C8AEE1F9BF1} - System32\Tasks\{D1B59439-F8C7-4009-8BF9-399F8519189E} => pcalua.exe -a G:\Instalačky\Hry\Šachy\YeaChess\YeaChess_setup.exe -d G:\Instalačky\Hry\Šachy\YeaChess
Task: {53C599EF-D9B4-444F-9B3C-181D6D9634A5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {54441870-0E8E-49F5-93A7-1E169BF5A3C2} - System32\Tasks\{1282BFA7-186B-471F-94F4-A8473C8A1611} => pcalua.exe -a "C:\Program Files\City Interactive\MOTORM4X Offroad Extreme\MOTORM4XOffroadExtremeCZ.exe" -d "C:\Program Files\City Interactive\MOTORM4X Offroad Extreme"
Task: {5B1253A5-4D4E-4F7D-A68C-7983478B1F15} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {5CE5009F-1260-496A-AE13-40BEF27A8EFB} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {5CFC6547-F84F-4299-A6D9-75E2E9304389} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot => C:\windows\system32\MusNotification.exe [2015-08-09] (Microsoft Corporation)
Task: {5E4B966E-4F7F-4F1A-B448-930FA0E424E2} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {61C640D9-C72B-4E86-AEC0-4BFCD4586879} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {6242D18B-05BC-4E1D-A454-B868E625E9F1} - System32\Tasks\{476E53AD-B19C-4D41-851C-83224F4610E4} => pcalua.exe -a "G:\Instalačky\Hry\GTA San Andreas\gtasa120cz.exe" -d "G:\Instalačky\Hry\GTA San Andreas"
Task: {6316CE80-244C-4CFF-B6A6-E47B83F94E9B} - System32\Tasks\{85F5F6AB-72FC-4198-B6FD-E041AB4E7E86} => pcalua.exe -a "G:\Instalačky\Správa počítače\HijackThis.exe" -d "G:\Instalačky\Správa počítače"
Task: {6451D5E9-DC34-446B-AD5B-9D75EFC36B38} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\WINDOWS\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)
Task: {6CBC2967-4165-44F1-A9A5-A63F5DEDB1E9} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [2015-08-09] (Microsoft Corporation)
Task: {6CC2569D-EFD0-42A4-A0C0-FE506F7AF0ED} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\WINDOWS\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {6CD9C59D-DF1A-46EF-916A-73279EA31679} - System32\Tasks\Microsoft\Windows\RetailDemo\CleanupOfflineContent
Task: {7135AB65-C102-40AF-8A95-750F84E26CA4} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display => C:\windows\system32\MusNotification.exe [2015-08-09] (Microsoft Corporation)
Task: {73D5DAA5-BC01-414E-A69D-B35AF066B75B} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {774A65FA-58F3-4431-8C46-7078368F6A3E} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\WINDOWS\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)
Task: {784017A0-41E3-423C-B4F3-CF8F69DF8C64} - System32\Tasks\Microsoft\Windows\LanguageComponentsInstaller\Installation
Task: {797930BC-B506-4F11-9896-4C928674405C} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot => C:\WINDOWS\system32\usoclient.exe [2015-07-10] (Microsoft Corporation)
Task: {7EA043E0-2192-4D94-9C60-7D3C4743D53C} - System32\Tasks\{66A67963-CF16-450B-9E8F-E176D9D9B93D} => pcalua.exe -a "G:\Instalačky\Internetová televize a rádia\Setup TV\setup.exe" -d "G:\Instalačky\Internetová televize a rádia\Setup TV"
Task: {825EB94B-B87F-4208-A687-7EC05A994AC8} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8800B598-E634-46DF-84AE-4281E0056E78} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {883A0EDC-B064-4AFB-BED6-BAB95C44196F} - System32\Tasks\{2E5EA928-3063-4C5C-B659-29D23548AACB} => C:\Users\Public\Sony Online Entertainment\Installed Games\Bullet Run\LaunchPad.exe [2012-08-07] (Sony Online Entertainment, LLC)
Task: {88742C4E-AF27-4EC0-AA61-61526B2F4601} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install => C:\WINDOWS\system32\usoclient.exe [2015-07-10] (Microsoft Corporation)
Task: {88EC7AF4-A3EF-4386-8718-B07C18352180} - System32\Tasks\{078C2638-0F11-4E6A-B8A4-8AD46B0EA1BB} => pcalua.exe -a "G:\FŠCHM\instalačky\Hry a programy\WinCH2_setup.exe" -d "G:\FŠCHM\instalačky\Hry a programy"
Task: {89F0F489-8CBE-472F-B147-A85FB55AD888} - System32\Tasks\{63CA6418-8E23-4758-9903-CFF40C10E908} => pcalua.exe -a "G:\Instalačky\Správa počítače\!! Antivirové programy\Mwav.exe" -d "G:\Instalačky\Správa počítače\!! Antivirové programy"
Task: {8A19530F-BBB4-41BC-A00F-9D28393A57EF} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {8B03A27E-AC1F-4FE4-9FD9-640ED4E7D0DF} - System32\Tasks\{7FB65A87-A109-4CA5-B7E0-0D790571227E} => pcalua.exe -a "C:\Program Files\Rockstar Games\GTA San Andreas\text\gtasa120cz.exe" -d "C:\Program Files\Rockstar Games\GTA San Andreas\text"
Task: {8BD8D26D-9B78-4CF6-9D46-9E9201ECED6B} - System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Reboot => C:\WINDOWS\system32\MusNotification.exe [2015-08-09] (Microsoft Corporation)
Task: {8E936232-5296-407A-93EB-5EB6E3CB3C38} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {93723144-5D73-49A4-8802-B66F9E89E54E} - System32\Tasks\{3CFB85D5-65BB-43E7-95AC-06B20AABCD4E} => pcalua.exe -a "G:\Instalačky\Hudba a video\Hudba\Magic Flac to Mp3 converter v.3.71\flac2mp3.exe" -d "G:\Instalačky\Hudba a video\Hudba\Magic Flac to Mp3 converter v.3.71"
Task: {953A2585-DB73-4808-9FFE-8461D65AE44C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {99B5FCC6-AB85-4505-905A-82CB47CF40AB} - System32\Tasks\{A68AAF46-D59F-457B-ABE1-6235CFA0E289} => pcalua.exe -a "C:\!! Torrenty\!! Hotovo\Magic Flac to Mp3 converter v.3.71\flac2mp3.exe" -d "C:\!! Torrenty\!! Hotovo\Magic Flac to Mp3 converter v.3.71"
Task: {9A221177-0495-4423-8A93-E19927BC82E3} - System32\Tasks\{96381C5F-3168-43F0-BC27-17D147A0F880} => pcalua.exe -a C:\Users\Petr\Downloads\ytd-0.95.exe -d "C:\Program Files\Mozilla Firefox"
Task: {9B928729-E5DF-4D0B-BC9A-22ABE2678EDC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {9BDC4571-51E3-482B-8842-24C64128F03E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9CD5AF71-D063-4292-8C2E-02A9D60027FF} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {9E2138AD-28F7-4475-AF66-EEA04BEDF23C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {A09D017E-BEA9-4798-B5BC-8F5F077C9C28} - System32\Tasks\{77079AD1-23F3-4A92-80AD-2EA135A68CC2} => pcalua.exe -a "C:\!! Torrenty\!! Hotovo\VirtuaNES\VirtuaNES.exe" -d "C:\!! Torrenty\!! Hotovo\VirtuaNES"
Task: {A1DF77AF-54E1-4D3F-A809-022C7E858D0B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {A589635E-0285-444B-9648-D53FDE73BD52} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {AC2ECFA3-8D55-4933-8FBE-2A9C69DB596E} - System32\Tasks\{D66FCA5F-E86C-4721-8DBE-23C6D55305A3} => pcalua.exe -a "C:\!! Torrenty\Stažené soubory\BluePilgrim.exe" -d "C:\Program Files\Mozilla Firefox"
Task: {AE07B768-86B5-4E60-A0EC-8AC655C643C3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {AE7BA7D5-2965-414C-97BE-081CE80DD359} - System32\Tasks\{28AB6A2F-0C04-4A68-B348-B123FCBC142D} => pcalua.exe -a "G:\Instalačky\Hry a programy\Programy\Test z dějepisu\START.EXE" -d "G:\Instalačky\Hry a programy\Programy\Test z dějepisu"
Task: {B495FC94-C2DC-48F1-A041-160D22785647} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-17] (Adobe Systems Incorporated)
Task: {B8BF8E24-25CF-4AC4-A410-E34B3E3E103A} - System32\Tasks\{84F43999-0F6C-4F42-989D-E6BB51CB1538} => pcalua.exe -a E:\Directx8\dxsetup.exe -d E:\Directx8
Task: {B901755F-CAFD-4049-832F-6FD03FBA775F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {B9F7D20A-8A9C-4D03-A8B5-5B886D905094} - System32\Tasks\{38622171-7C94-4BFD-BA7E-ECCAAB5315B1} => pcalua.exe -a "D:\Program Files\!! HERNÍ VÝBĚR\Nuklearni Karel\uninstall.exe" -d "D:\Program Files\!! HERNÍ VÝBĚR\Nuklearni Karel"
Task: {BB8294A5-2074-412A-B206-ED229DED5564} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {BB9729AA-4F75-4005-9F01-AFA0546C5651} - System32\Tasks\{9CB38E05-79D0-43A8-9E6F-460A4AC1A1B5} => pcalua.exe -a "G:\Instalačky\Hry a programy\Hry\Emulátory\DOSBox0.72-win32-installer.exe" -d "G:\Instalačky\Hry a programy\Hry\Emulátory"
Task: {C4D716A7-1864-4576-87CD-E0755757C2AE} - System32\Tasks\{698C4DDC-6ACA-46BA-BCF3-2701EAA04D87} => pcalua.exe -a G:\Instalačky\Hry\Easter_Eggy.exe -d "C:\Program Files\Mozilla Firefox"
Task: {C635A47C-00A8-49EA-8F70-46CB8608CA7A} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {C777FBAD-953B-4AA8-A892-38486F327D51} - System32\Tasks\{8612F7B7-C29D-4FD4-ACD0-94875E607165} => C:\Program Files\Rockstar Games\Grand Theft Auto Vice City\gta-vc.exe [2006-06-01] ()
Task: {C7F8DC2D-9D31-4DFE-A34C-1A5E18943525} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\WINDOWS\system32\ClipUp.exe [2015-08-09] (Microsoft Corporation)
Task: {D021B2CF-B2DF-4D83-9F2D-86D9270F1336} - System32\Tasks\{35D326F5-16EB-4C54-A17E-BBCA847D24D0} => pcalua.exe -a "C:\!! Torrenty\Stažené soubory\Shockwave_Installer_Full.exe" -d "C:\!! Torrenty\Stažené soubory"
Task: {D54D6019-D7D2-425D-A182-3A752C155021} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-05-27] (Google Inc.)
Task: {D64C793E-E12D-4AB1-AA95-08E270B607FF} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DC7194AB-760D-4307-9A76-ED53A48778AF} - System32\Tasks\{23F7530F-3806-482D-87CB-261684A5D04D} => pcalua.exe -a "C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\WWTExplorer.exe" -d "C:\Program Files\Microsoft Research\Microsoft WorldWide Telescope\"
Task: {DCE47771-2DCD-4F76-8007-50EEAB9A90A4} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {DD0E3555-7157-47DC-B96D-AB9D758E74DC} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {DD87F70B-C8AE-4ECD-9AFC-288536510545} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics => C:\WINDOWS\system32\disksnapshot.exe [2015-07-10] (Microsoft Corporation)
Task: {E0180085-0F91-427B-90DF-9C544E39D03C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E121EB22-3F24-4939-844E-9E850B16729E} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E1BCCB3C-90EF-47B6-A190-506B7166DA76} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd)
Task: {E3FBBA84-1DB8-48C0-9156-90AB8123E65E} - System32\Tasks\Microsoft\Windows\Sysmain\ResPriStaticDbSync
Task: {E80F60AE-C525-4960-8CB0-098D3534D880} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {E834DF42-8D06-4FBC-A3CC-055E0DDA0DF5} - System32\Tasks\{4C11B2A2-B4EC-4C13-A24B-5107A384512C} => pcalua.exe -a E:\akcni\3dbod\3dbod.exe -d E:\akcni\3dbod
Task: {EC96AA74-01CC-49D2-B088-BA8A999BFEA2} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {ED88D42D-7F26-44D3-AC67-69C2ECC8C5E8} - System32\Tasks\Microsoft\Windows\SetupSQMTask => C:\WINDOWS\SYSTEM32\OOBE\SETUPSQM.EXE [2015-07-10] (Microsoft Corporation)
Task: {F31D7EF8-31AF-4E29-B9A4-6152E173C5CA} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {F337B893-9046-4885-827B-4BDB0427C573} - System32\Tasks\{5BD39B76-81C7-48FB-B9F0-D4A150B105D3} => pcalua.exe -a "G:\Instalačky\Internetová televize a rádia\aglotze_v11.exe" -d "C:\Program Files\Mozilla Firefox"
Task: {F5D7551D-82E9-4FCF-8542-EAFA4ECB221E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-13] (Adobe Systems Incorporated)
Task: {F86DE5E1-6B10-40C9-AD80-3EEB017200A7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F9532711-C08E-4236-A173-10235C5D5411} - System32\Tasks\{90F290AE-2AA4-4250-BEDA-5A0C87F93D86} => pcalua.exe -a "C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\moha_setup.exe" -d "C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\"
Task: {FB6B539D-57C2-4E39-98FD-C9D2BF921B63} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\WINDOWS\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {FCAAE9DA-081D-46B2-B303-CFE8A19B687C} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {FED525A2-3A53-46A2-9229-6DA32C22795B} - System32\Tasks\{9F709BFC-9180-4007-8959-16B67F532282} => pcalua.exe -a "G:\Instalačky\SMS, ICQ, Skype\Esmska-0.22.2-setup.exe" -d "G:\Instalačky\SMS, ICQ, Skype"

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-09 13:39 - 2015-08-09 13:39 - 00025088 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-09 13:40 - 2015-08-09 13:40 - 00301056 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-08-09 12:47 - 2015-08-07 06:26 - 00106288 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 01769056 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-09 20:24 - 2015-07-30 06:24 - 01769056 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2012-07-10 08:48 - 2009-11-16 20:31 - 00069632 _____ () C:\Program Files\PSPad editor\PSPadShell.dll
2015-05-06 09:10 - 2015-07-24 06:22 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\Update Core\detoured.dll
2015-07-10 10:24 - 2015-07-10 10:24 - 00288768 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-08-12 08:48 - 2015-08-03 02:57 - 04317696 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 10:25 - 2015-07-10 15:22 - 00377856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-12 08:48 - 2015-08-03 02:55 - 01181184 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-12 08:48 - 2015-08-03 02:55 - 01425920 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2011-11-08 16:17 - 2009-02-06 19:52 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL
2011-11-08 16:17 - 2009-03-26 15:46 - 00148480 _____ () C:\Windows\SYSTEM32\APOMngr.DLL
2015-07-17 19:34 - 2015-07-17 19:34 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Delapp.bat:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\MpSigStub.exe:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\mshtmlmedia.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\MsSpellCheckingFacility.exe:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvaudcap32v.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispco3234725.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispco3235012.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispco3235286.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispco3235306.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispco3235330.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco3234725.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco3235012.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco3235286.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco3235306.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\nvdispgenco3235330.dll:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\avgfwd6x.sys:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\avglogx.sys:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mbam.sys:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mbamchameleon.sys:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\mwac.sys:$CmdTcID
AlternateDataStreams: C:\WINDOWS\system32\Drivers\nvvad32v.sys:$CmdTcID
AlternateDataStreams: C:\Users\Petr\Desktop\islamofilie-v-kostce.pdf:$CmdTcID
AlternateDataStreams: C:\Users\Petr\Desktop\islamofilie-v-kostce.pdf:$CmdZnID

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
Keybord not present. Press Enter to continue

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 14 srp 2015 08:54

Zde je druhá část logu addition.exe:


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-se.com -> 1-se.com

There are 11735 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 213.46.172.37 - 213.46.172.36
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BitTorrent.lnk => C:\Windows\pss\BitTorrent.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Registrace produktu.lnk => C:\Windows\pss\Logitech . Registrace produktu.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Petr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk => C:\Windows\pss\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk.Startup
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: LogitechQuickCamRibbon => "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
MSCONFIG\startupreg: NokiaMusic FastStart => "C:\Program Files\Nokia\Nokia Music Player\NokiaMusicPlayer.exe" /command:faststart
MSCONFIG\startupreg: NvBackend => "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: ShadowPlay => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Petr\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
HKLM\...\StartupApproved\Run: => "COMODO Internet Security"
HKLM\...\StartupApproved\Run: => "ShadowPlay"
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\StartupApproved\Run: => "CCleaner Monitoring"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-32bit] => (Allow) LPort=808
FirewallRules: [{155B6193-9A6E-4A11-8608-B085E51A09D3}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{F9D43F74-9904-4EFF-9A75-AD0493546B1B}] => (Allow) C:\Program Files\AVG\AVG2015\avgemcx.exe
FirewallRules: [{767645B6-2CCE-432C-AB0B-191D6B89C6D1}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{61FBF7F0-537F-4F31-9F41-FB971DBE62B4}] => (Allow) C:\Program Files\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{287A7A5C-C547-400E-9087-203055A63CC7}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{1F29D365-3215-4B82-BE90-AC72A58D373F}] => (Allow) C:\Program Files\AVG\AVG2015\avgnsx.exe
FirewallRules: [{953E115A-FB96-4B37-AAA9-5BF9A5DC46F7}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{D1FA21D5-71A0-43D4-84B2-D6584DA6CFF5}] => (Allow) C:\Program Files\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{89340BCC-5305-46E7-B9CB-3A9226CE49E6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5829AAE5-A6B5-4302-9809-A024D50966DC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{3EED9121-A8E2-4B60-9819-EB36851850B4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{3F6D6A16-53FD-4FDC-9944-C249DBDB8CFE}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{90B02225-470C-4B6F-BE30-29A09FEE231C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{F59B88ED-AE32-4650-93BE-61669F301C55}] => (Allow) C:\Program Files\Parom.TV\paromplayer.exe
FirewallRules: [{47F8D8AC-187D-4C33-A4C4-EAE237661504}] => (Allow) C:\Program Files\Parom.TV\paromplayer.exe
FirewallRules: [UDP Query User{E4F926A8-B972-4D4D-97E7-37704D0A4CBC}C:\program files\tvuplayer\tvuplayer.exe] => (Allow) C:\program files\tvuplayer\tvuplayer.exe
FirewallRules: [TCP Query User{355772AB-2CCA-478C-926F-190A25E8D97C}C:\program files\tvuplayer\tvuplayer.exe] => (Allow) C:\program files\tvuplayer\tvuplayer.exe
FirewallRules: [UDP Query User{6FAA17A2-F798-4A88-80BA-1DC16865D208}C:\users\petr\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\petr\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{892043FB-C949-4528-ADAB-BD0A2ACAC92A}C:\users\petr\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\petr\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{E4B921E9-F946-496E-B264-D10F4E775572}C:\users\petr\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\petr\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{13758209-EC29-4385-B776-4B0090426886}C:\users\petr\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\petr\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{9A1AC8A3-11A0-4E5C-A37E-ABF0F625158F}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{AF9D5409-291D-44E7-A426-6B1EE187EE87}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{F769B642-6D1B-4937-A85F-D9681161D5FE}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{2BB0AEB9-295E-4DC6-8976-204095560EA3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{EA4A3B86-0532-441C-B39D-737AC2DABFFC}] => (Allow) C:\Program Files\Winamp\winamp.exe
FirewallRules: [{64E0B41F-6650-4645-9C1E-036186E2BDE0}] => (Allow) C:\Program Files\Winamp\winamp.exe
FirewallRules: [{7DEB36B4-50B5-45BC-BE60-FF7A6C0D84AE}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{9B9542D4-2989-4CC8-9DC3-C56855B3F9E1}] => (Allow) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [UDP Query User{67E061F1-7FD9-4D70-B5AD-39CB6A952F3D}C:\users\petr\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\petr\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{33CB591A-DAAE-4329-B273-D61BA7C587C3}C:\users\petr\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\petr\appdata\roaming\spotify\spotify.exe
FirewallRules: [{9C27501F-0A96-424D-9382-9D74DEFDFA1E}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{F76A4799-68AB-4717-81A6-F86C1547CC52}] => (Allow) C:\Program Files\BitTorrent\BitTorrent.exe
FirewallRules: [{A1A810B8-952D-4553-BCBB-D62176D9BF7A}] => (Allow) C:\Program Files\BitTorrent\BitTorrent.exe
FirewallRules: [UDP Query User{B367FDF1-6D97-46FD-BBAF-E02ED1FB99F2}C:\users\petr\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\petr\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [TCP Query User{B9FDF405-BD9C-4B05-AB5F-3A3BB484B0DE}C:\users\petr\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\petr\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{B68D9FC7-FE51-40E0-9B7B-8CBCC080054D}G:\instalačky\vypalování, winzip, stahování dat, apod\bittorrent (7.5).exe] => (Allow) G:\instalačky\vypalování, winzip, stahování dat, apod\bittorrent (7.5).exe
FirewallRules: [TCP Query User{4E591382-6A78-41FB-A1E0-353513242C54}G:\instalačky\vypalování, winzip, stahování dat, apod\bittorrent (7.5).exe] => (Allow) G:\instalačky\vypalování, winzip, stahování dat, apod\bittorrent (7.5).exe
FirewallRules: [UDP Query User{5C5D834A-3FB6-4950-8FFB-595C41B5D282}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [TCP Query User{908A9E04-C667-4E6B-80E3-A0933BB93BE1}C:\program files\videolan\vlc\vlc.exe] => (Allow) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [{594A00D1-EC04-4D21-95B9-7A546FA1351C}] => (Allow) C:\Program Files\Logitech\Vid HD\Vid.exe
FirewallRules: [{83BAFAC2-B9C1-431B-BA69-C9D1737C85F7}] => (Allow) C:\Program Files\Logitech\Vid HD\Vid.exe
FirewallRules: [{5431E2B5-A6BA-4326-9102-46CFBA334093}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{6D89690A-2DEB-44CC-ACF0-16B7FC4A277F}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{62ADCCCE-6A2F-458C-B19C-38E1FAD5F3E5}] => (Allow) C:\Windows\System32\PnkBstrB.exe
FirewallRules: [{415820F1-B21B-4C06-A6A5-686E18A2D55E}] => (Allow) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [UDP Query User{0DD80B20-5040-43CF-A2B7-95EFAA84C98A}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [TCP Query User{C3D7AB9F-9CDF-40DB-8676-757A326FFE81}C:\program files\internet explorer\iexplore.exe] => (Allow) C:\program files\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{139EC371-4B05-41A6-B684-8BFA7B4279EB}C:\program files\tapinradio\tapinradio.exe] => (Allow) C:\program files\tapinradio\tapinradio.exe
FirewallRules: [TCP Query User{9A45832F-924C-43E8-BA2C-5757A0483163}C:\program files\tapinradio\tapinradio.exe] => (Allow) C:\program files\tapinradio\tapinradio.exe
FirewallRules: [{CD1EDB1B-3BB7-4F3D-A51E-B04063ACC31C}] => (Allow) C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [{322E4B0D-84AE-4D5E-B662-46E77B775100}] => (Allow) C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe
FirewallRules: [{B203DAF3-E33C-4AFB-9F74-5C781DF98FBD}] => (Allow) LPort=5353
FirewallRules: [{AA80AA3B-C6C3-433F-8065-AB3F7500FBF7}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{7A255E50-C6CF-412B-89C3-9B117E0F74E7}] => (Allow) C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{CCE1BE80-34DF-4CB0-BAB1-72AC9B8333AC}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/14/2015 08:33:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: OHub.exe, verze: 16.0.6106.2350, časové razítko: 0x55c40ea5
Název chybujícího modulu: ntdll.dll, verze: 10.0.10240.16430, časové razítko: 0x55c599e6
Kód výjimky: 0xc0000374
Posun chyby: 0x000e1267
ID chybujícího procesu: 0x6f4
Čas spuštění chybující aplikace: 0xOHub.exe0
Cesta k chybující aplikaci: OHub.exe1
Cesta k chybujícímu modulu: OHub.exe2
ID zprávy: OHub.exe3
Úplný název chybujícího balíčku: OHub.exe4
ID aplikace související s chybujícím balíčkem: OHub.exe5

Error: (08/13/2015 05:22:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchUI.exe verze 10.0.10240.16425 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: ebc

Čas spuštění: 01d0d5d73b0da5d9

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

ID hlášení: 2968dc77-41cf-11e5-93d8-001d7daf29d4

Úplný název balíčku s chybou: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy

ID aplikace související s balíčkem s chybou: CortanaUI

Error: (08/13/2015 05:22:51 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: intel)
Description: Balíček Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy+CortanaUI se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (08/13/2015 05:18:14 PM) (Source: MsiInstaller) (EventID: 11316) (User: intel)
Description: Produkt: COMODO Internet Security - Chyba 1316 Zadaný účet již existuje.

Error: (08/13/2015 05:03:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: OHub.exe, verze: 16.0.6106.2350, časové razítko: 0x55c40ea5
Název chybujícího modulu: ntdll.dll, verze: 10.0.10240.16430, časové razítko: 0x55c599e6
Kód výjimky: 0xc0000374
Posun chyby: 0x000e1267
ID chybujícího procesu: 0x19e8
Čas spuštění chybující aplikace: 0xOHub.exe0
Cesta k chybující aplikaci: OHub.exe1
Cesta k chybujícímu modulu: OHub.exe2
ID zprávy: OHub.exe3
Úplný název chybujícího balíčku: OHub.exe4
ID aplikace související s chybujícím balíčkem: OHub.exe5

Error: (08/13/2015 04:27:51 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (08/13/2015 03:33:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AUDIODG.EXE, verze: 10.0.10240.16384, časové razítko: 0x559f3cf8
Název chybujícího modulu: P17APO32.dll, verze: 1.0.6.0, časové razítko: 0x49de0d5a
Kód výjimky: 0xc0000005
Posun chyby: 0x0001b8d5
ID chybujícího procesu: 0x3c8
Čas spuštění chybující aplikace: 0xAUDIODG.EXE0
Cesta k chybující aplikaci: AUDIODG.EXE1
Cesta k chybujícímu modulu: AUDIODG.EXE2
ID zprávy: AUDIODG.EXE3
Úplný název chybujícího balíčku: AUDIODG.EXE4
ID aplikace související s chybujícím balíčkem: AUDIODG.EXE5

Error: (08/13/2015 10:44:31 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: OHub.exe, verze: 16.0.6106.2350, časové razítko: 0x55c40ea5
Název chybujícího modulu: ntdll.dll, verze: 10.0.10240.16430, časové razítko: 0x55c599e6
Kód výjimky: 0xc0000374
Posun chyby: 0x000e1267
ID chybujícího procesu: 0x18a8
Čas spuštění chybující aplikace: 0xOHub.exe0
Cesta k chybující aplikaci: OHub.exe1
Cesta k chybujícímu modulu: OHub.exe2
ID zprávy: OHub.exe3
Úplný název chybujícího balíčku: OHub.exe4
ID aplikace související s chybujícím balíčkem: OHub.exe5

Error: (08/13/2015 08:17:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: AUDIODG.EXE, verze: 10.0.10240.16384, časové razítko: 0x559f3cf8
Název chybujícího modulu: P17APO32.dll, verze: 1.0.6.0, časové razítko: 0x49de0d5a
Kód výjimky: 0xc0000005
Posun chyby: 0x0001b8d5
ID chybujícího procesu: 0x1ad0
Čas spuštění chybující aplikace: 0xAUDIODG.EXE0
Cesta k chybující aplikaci: AUDIODG.EXE1
Cesta k chybujícímu modulu: AUDIODG.EXE2
ID zprávy: AUDIODG.EXE3
Úplný název chybujícího balíčku: AUDIODG.EXE4
ID aplikace související s chybujícím balíčkem: AUDIODG.EXE5

Error: (08/12/2015 08:43:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: OHub.exe, verze: 16.0.6106.2350, časové razítko: 0x55c40ea5
Název chybujícího modulu: ntdll.dll, verze: 10.0.10240.16430, časové razítko: 0x55c599e6
Kód výjimky: 0xc0000374
Posun chyby: 0x000e1267
ID chybujícího procesu: 0x24c0
Čas spuštění chybující aplikace: 0xOHub.exe0
Cesta k chybující aplikaci: OHub.exe1
Cesta k chybujícímu modulu: OHub.exe2
ID zprávy: OHub.exe3
Úplný název chybujícího balíčku: OHub.exe4
ID aplikace související s chybujícím balíčkem: OHub.exe5


System errors:
=============
Error: (08/14/2015 08:37:28 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba COMODO Internet Security Helper Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (08/13/2015 05:23:07 PM) (Source: DCOM) (EventID: 10010) (User: intel)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}

Error: (08/13/2015 05:23:07 PM) (Source: DCOM) (EventID: 10010) (User: intel)
Description: {3EEF301F-B596-4C0B-BD92-013BEAFCE793}

Error: (08/13/2015 05:23:07 PM) (Source: DCOM) (EventID: 10010) (User: intel)
Description: {9AA46009-3CE0-458A-A354-715610A075E6}

Error: (08/13/2015 05:23:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_Session1 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2015 05:04:42 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (08/13/2015 04:48:45 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Adaptér naslouchání Net.Tcp závisí na službě Služba sdílení portů Net.Tcp, která neuspěla při spuštění v důsledku následující chyby:
%%1058

Error: (08/13/2015 04:48:44 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: Tento počítač je nakonfigurován jako člen pracovní skupiny, nikoliv jako
člen domény. Přihlašovací služba Netlogon nepotřebuje být spuštěna v této
konfiguraci.

Error: (08/13/2015 04:47:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_Session1 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2015 04:42:11 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


Microsoft Office:
=========================

CodeIntegrity:
===================================
Date: 2015-08-14 08:39:22.118
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard32.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-08-13 17:10:57.363
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard32.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-08-13 16:49:32.478
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\guard32.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-08-11 13:10:00.240
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:10:00.171
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:10:00.111
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:10:00.032
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:09:59.995
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:09:59.944
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-08-11 13:09:58.400
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume4\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU E8200 @ 2.66GHz
Percentage of memory in use: 39%
Total physical RAM: 3326.49 MB
Available physical RAM: 2013.55 MB
Total Virtual: 6654.49 MB
Available Virtual: 5070.16 MB

==================== Drives ================================

Drive c: (win7) (Fixed) (Total:151.61 GB) (Free:59.46 GB) NTFS
Drive d: (winXP) (Fixed) (Total:146.48 GB) (Free:126 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive e: (GTA VICE CITY) (CDROM) (Total:1.39 GB) (Free:0 GB) CDFS
Drive f: (Dokumenty) (Fixed) (Total:244.14 GB) (Free:124.34 GB) NTFS
Drive g: (Multimedia) (Fixed) (Total:687.37 GB) (Free:138.09 GB) NTFS
Drive h: (Win7) (Fixed) (Total:111.79 GB) (Free:73.1 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: A2EBA2EB)
Partition 1: (Not Active) - (Size=244.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=687.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 4310430F)
Partition 1: (Active) - (Size=146.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=151.6 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: E3BB742E)
Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS)

==================== End of log ============================
Keybord not present. Press Enter to continue

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 14 srp 2015 11:56

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [647888 2015-08-05] (COMODO)
R1 cmdhlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30400 2015-08-05] (COMODO)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\system32\Drivers\cmdguard.cat
C:\WINDOWS\system32\Drivers\inspect.cat
C:\WINDOWS\system32\Drivers\cmdhlp.cat
C:\ProgramData\Comodo
C:\WINDOWS\system32\Drivers\cmdguard.sys
C:\WINDOWS\system32\Drivers\cmdhlp.sys
C:\WINDOWS\system32\Drivers\cmderd.sys
C:\WINDOWS\system32\cmdcsr.dll
C:\WINDOWS\system32\guard32.dll
C:\WINDOWS\system32\cmdvrt32.dll
C:\WINDOWS\system32\cmdkbd32.dll
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}
COMODO Internet Security (HKLM\...\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}) (Version: 5.0.32580.1142 - COMODO Group Inc.)
Task: {36EF8C82-0B11-4D9F-8D02-07B59749910D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {8800B598-E634-46DF-84AE-4281E0056E78} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {8E936232-5296-407A-93EB-5EB6E3CB3C38} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {953A2585-DB73-4808-9FFE-8461D65AE44C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {9B928729-E5DF-4D0B-BC9A-22ABE2678EDC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {9BDC4571-51E3-482B-8842-24C64128F03E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9E2138AD-28F7-4475-AF66-EEA04BEDF23C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {AE07B768-86B5-4E60-A0EC-8AC655C643C3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B901755F-CAFD-4049-832F-6FD03FBA775F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {BB8294A5-2074-412A-B206-ED229DED5564} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {E80F60AE-C525-4960-8CB0-098D3534D880} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-se.com -> 1-se.com

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Delme.bat
C:\WINDOWS\system32\SETC243.tmp

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
akiller
Level 3
Level 3
Příspěvky: 558
Registrován: listopad 10
Bydliště: Nothingtown
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod akiller » 14 srp 2015 12:31

Včera jsi se ptal na problémy, tak dneska mohu říct, že před chvílí jsem ze stejného důvodu restartoval počítač (sekl se, z repráků vycházel zvuk zaseknutého videa, nereagoval, musel jsem ho restartovat).

https://www.virustotal.com/cs/file/ba645301f04a1fce07f13362a4b815baf2be395ee52ddc6c1b3bb86348a55c40/analysis/1439547549/

Druhý soubor nemohu najít. A že jsem se fakt snažil :evil:


Fix result of Farbar Recovery Scan Tool (x86) Version:13-08-2015
Ran by Petr (2015-08-14 12:06:27) Run:1
Running from C:\Users\Petr\Desktop
Loaded Profiles: Petr (Available Profiles: Petr)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
R1 cmdGuard; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [647888 2015-08-05] (COMODO)
R1 cmdhlp; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [30400 2015-08-05] (COMODO)
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\system32\Drivers\cmdguard.cat
C:\WINDOWS\system32\Drivers\inspect.cat
C:\WINDOWS\system32\Drivers\cmdhlp.cat
C:\ProgramData\Comodo
C:\WINDOWS\system32\Drivers\cmdguard.sys
C:\WINDOWS\system32\Drivers\cmdhlp.sys
C:\WINDOWS\system32\Drivers\cmderd.sys
C:\WINDOWS\system32\cmdcsr.dll
C:\WINDOWS\system32\guard32.dll
C:\WINDOWS\system32\cmdvrt32.dll
C:\WINDOWS\system32\cmdkbd32.dll
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}
COMODO Internet Security (HKLM\...\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}) (Version: 5.0.32580.1142 - COMODO Group Inc.)
Task: {36EF8C82-0B11-4D9F-8D02-07B59749910D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {8800B598-E634-46DF-84AE-4281E0056E78} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {8E936232-5296-407A-93EB-5EB6E3CB3C38} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {953A2585-DB73-4808-9FFE-8461D65AE44C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {9B928729-E5DF-4D0B-BC9A-22ABE2678EDC} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {9BDC4571-51E3-482B-8842-24C64128F03E} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9E2138AD-28F7-4475-AF66-EEA04BEDF23C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {AE07B768-86B5-4E60-A0EC-8AC655C643C3} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B901755F-CAFD-4049-832F-6FD03FBA775F} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {BB8294A5-2074-412A-B206-ED229DED5564} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {E80F60AE-C525-4960-8CB0-098D3534D880} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\...\1-se.com -> 1-se.com

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\COMODO Internet Security => value removed successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully.
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
cmdGuard => service not found.
cmdhlp => service not found.
idsvc => service removed successfully.
wpcsvc => service removed successfully.
C:\WINDOWS\system32\Drivers\cmdguard.cat => moved successfully.
C:\WINDOWS\system32\Drivers\inspect.cat => moved successfully.
C:\WINDOWS\system32\Drivers\cmdhlp.cat => moved successfully.
C:\ProgramData\Comodo => moved successfully.
C:\WINDOWS\system32\Drivers\cmdguard.sys => moved successfully.
C:\WINDOWS\system32\Drivers\cmdhlp.sys => moved successfully.
C:\WINDOWS\system32\Drivers\cmderd.sys => moved successfully.
C:\WINDOWS\system32\cmdcsr.dll => moved successfully.
C:\WINDOWS\system32\guard32.dll => moved successfully.
C:\WINDOWS\system32\cmdvrt32.dll => moved successfully.
C:\WINDOWS\system32\cmdkbd32.dll => moved successfully.
FW: COMODO Firewall (Enabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E} => The item is protected. Make sure the software is uninstalled and its services is removed.
COMODO Internet Security (HKLM\...\{FD8E178D-8B4E-42DA-B434-EFF270329B1C}) (Version: 5.0.32580.1142 - COMODO Group Inc.) => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{36EF8C82-0B11-4D9F-8D02-07B59749910D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{36EF8C82-0B11-4D9F-8D02-07B59749910D}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8800B598-E634-46DF-84AE-4281E0056E78}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8800B598-E634-46DF-84AE-4281E0056E78}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E936232-5296-407A-93EB-5EB6E3CB3C38}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E936232-5296-407A-93EB-5EB6E3CB3C38}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{953A2585-DB73-4808-9FFE-8461D65AE44C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{953A2585-DB73-4808-9FFE-8461D65AE44C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B928729-E5DF-4D0B-BC9A-22ABE2678EDC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B928729-E5DF-4D0B-BC9A-22ABE2678EDC}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9BDC4571-51E3-482B-8842-24C64128F03E}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BDC4571-51E3-482B-8842-24C64128F03E}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9E2138AD-28F7-4475-AF66-EEA04BEDF23C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E2138AD-28F7-4475-AF66-EEA04BEDF23C}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AE07B768-86B5-4E60-A0EC-8AC655C643C3}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE07B768-86B5-4E60-A0EC-8AC655C643C3}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B901755F-CAFD-4049-832F-6FD03FBA775F}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B901755F-CAFD-4049-832F-6FD03FBA775F}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{BB8294A5-2074-412A-B206-ED229DED5564}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB8294A5-2074-412A-B206-ED229DED5564}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E80F60AE-C525-4960-8CB0-098D3534D880}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E80F60AE-C525-4960-8CB0-098D3534D880}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\007guard.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008i.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\008k.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\00hq.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\010402.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0190-dialers.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\01i.info" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\02pmnzy5eo29bfk4.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\032439.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\05p.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\07ic5do2myz3vzpk.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\08nigbmwk43i01y6.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\093qpeuqpmz6ebfa.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0calories.net" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0cj.net" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\0scan.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-2005-search.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-britney-spears-nude.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-domains-registrations.com" => key removed successfully.
"HKU\S-1-5-21-1382680524-3974183494-2248916863-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\1-se.com" => key removed successfully.
EmptyTemp: => 451.1 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 12:06:55 ====
Keybord not present. Press Enter to continue

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod Orcus » 14 srp 2015 15:34

Po FRST to je stejné?
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 69 hostů