kontrola logu - poblázněné prohlížeče Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 05 říj 2015 09:29

2015-09-25 18:54 - 2015-07-11 03:02 - 00283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll
2015-09-25 18:54 - 2015-07-11 02:57 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2015-09-25 18:54 - 2015-07-11 02:43 - 00322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-09-25 18:54 - 2015-07-11 02:42 - 00191488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2015-09-25 18:54 - 2015-07-11 02:40 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-09-25 18:54 - 2015-07-11 02:34 - 00294912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2015-09-25 18:54 - 2015-07-10 17:47 - 00265480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-09-25 18:54 - 2015-07-10 17:00 - 01101792 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-09-25 18:54 - 2015-07-10 16:52 - 00335248 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-09-25 18:54 - 2015-07-10 12:59 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-09-25 18:54 - 2015-07-10 12:42 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hmkd.dll
2015-09-25 18:54 - 2015-07-10 12:10 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\hmkd.dll
2015-09-25 18:54 - 2015-07-10 12:05 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2015-09-25 18:54 - 2015-07-10 11:29 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2015-09-25 18:53 - 2015-08-11 10:50 - 00420352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2015-09-25 18:53 - 2015-08-11 10:38 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2015-09-25 18:53 - 2015-07-30 05:44 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-09-25 18:53 - 2015-07-18 09:28 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2015-09-25 18:53 - 2015-07-10 12:07 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\PackageInspector.exe
2015-09-25 18:38 - 2015-10-04 12:30 - 00000000 ____D C:\Users\frana\AppData\Local\CrashDumps
2015-09-25 18:30 - 2015-09-28 20:53 - 00001226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player PRO.lnk
2015-09-25 18:30 - 2015-09-26 12:00 - 00000000 ____D C:\Users\frana\AppData\Roaming\BSplayer PRO
2015-09-25 18:30 - 2015-09-25 18:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webteh
2015-09-25 18:30 - 2015-09-25 18:30 - 00000000 ____D C:\Program Files (x86)\Webteh
2015-09-25 18:28 - 2015-10-04 18:42 - 00000000 ____D C:\ProgramData\TEMP
2015-09-25 18:28 - 2015-10-04 13:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Your Uninstaller! 7
2015-09-25 18:28 - 2015-09-25 18:28 - 00000000 ____D C:\Users\frana\AppData\Roaming\URSoft
2015-09-25 18:27 - 2015-10-04 18:05 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-25 18:23 - 2015-09-28 20:53 - 00001160 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2015-09-25 18:23 - 2015-09-25 18:23 - 00000000 ____D C:\Users\frana\AppData\Roaming\WinRAR
2015-09-25 18:23 - 2015-09-25 18:23 - 00000000 ____D C:\Users\frana\AppData\Local\VS Revo Group
2015-09-25 18:23 - 2015-09-25 18:23 - 00000000 ____D C:\ProgramData\VS Revo Group
2015-09-25 18:23 - 2015-09-25 18:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-09-25 18:23 - 2015-09-25 18:23 - 00000000 ____D C:\Program Files\VS Revo Group
2015-09-25 18:23 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-09-25 18:15 - 2015-09-25 18:15 - 00000000 ____D C:\Users\frana\AppData\Roaming\AVAST Software
2015-09-25 18:13 - 2015-09-27 19:24 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-25 17:56 - 2015-09-28 09:52 - 00000000 ____D C:\Users\frana\AppData\LocalLow\Adobe
2015-09-25 17:56 - 2015-09-25 17:56 - 00000000 ____D C:\Users\frana\AppData\Local\CEF
2015-09-25 17:42 - 2015-10-01 10:38 - 00000000 ____D C:\Program Files (x86)\Opera
2015-09-25 17:42 - 2015-09-28 20:53 - 00001178 _____ C:\Users\Public\Desktop\Opera.lnk
2015-09-25 17:42 - 2015-09-25 17:42 - 00000000 ____D C:\Users\frana\AppData\Roaming\Opera Software
2015-09-25 17:42 - 2015-09-25 17:42 - 00000000 ____D C:\Users\frana\AppData\Local\Opera Software
2015-09-25 17:41 - 2015-09-29 19:04 - 00000000 ____D C:\Program Files (x86)\The KMPlayer
2015-09-25 17:41 - 2015-09-25 17:41 - 00000000 ____D C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2015-09-25 17:23 - 2015-10-05 07:32 - 00000000 ____D C:\Users\frana\AppData\Roaming\uTorrent
2015-09-25 17:23 - 2015-09-26 17:10 - 00000000 ____D C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2015-09-25 17:12 - 2015-10-01 15:07 - 00000000 ____D C:\Users\frana\AppData\Local\Adobe
2015-09-25 17:12 - 2015-09-25 17:12 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-09-25 17:11 - 2015-09-28 20:54 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2015-09-25 17:11 - 2015-09-28 20:54 - 00002112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2015-09-25 17:10 - 2015-10-01 15:05 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-25 17:10 - 2015-10-01 15:04 - 00000000 ____D C:\ProgramData\Adobe
2015-09-25 16:50 - 2015-09-28 20:54 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneDrive pro firmy.lnk
2015-09-25 16:50 - 2015-09-28 20:54 - 00002180 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype pro firmy 2016.lnk
2015-09-25 16:50 - 2015-09-26 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nástroje Microsoft Office 2016
2015-09-25 16:45 - 2015-09-28 20:54 - 00002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visio 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002212 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002194 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002188 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002186 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002144 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002110 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2015-09-25 16:45 - 2015-09-28 20:54 - 00002108 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2015-09-25 16:42 - 2015-10-02 06:18 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-25 16:42 - 2015-09-25 16:42 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-25 16:40 - 2015-10-01 09:32 - 00000000 ____D C:\Users\frana\AppData\LocalLow\Adblock Plus for IE
2015-09-25 16:40 - 2015-09-26 06:45 - 00000000 ____D C:\Program Files\Adblock Plus for IE
2015-09-25 16:35 - 2015-09-27 19:10 - 00000000 ____D C:\Users\frana\AppData\Roaming\Zoner
2015-09-25 16:35 - 2015-09-27 19:10 - 00000000 ____D C:\Users\frana\AppData\Local\Zoner
2015-09-25 16:35 - 2015-09-25 16:35 - 00000000 ____D C:\ProgramData\Zoner
2015-09-25 16:28 - 2015-09-25 16:28 - 00003584 _____ C:\Windows\SECOH-QAD.dll
2015-09-25 16:23 - 2015-09-25 16:24 - 00000000 ____D C:\Program Files\WinRAR
2015-09-25 16:23 - 2015-09-25 16:23 - 00000000 ____D C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-25 16:23 - 2015-09-25 16:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-09-25 13:54 - 2015-09-25 19:45 - 00000000 ____D C:\Windows\Panther
2015-09-25 13:54 - 2015-09-25 13:54 - 00008192 __RSH C:\BOOTSECT.BAK
2015-09-25 13:37 - 2015-09-25 13:37 - 00000000 ____D C:\Users\frana\AppData\Local\Macromedia
2015-09-25 13:32 - 2015-10-05 06:32 - 00004212 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{DD2DB02A-4FD0-4739-BFCC-86EF3A54F1D2}
2015-09-25 13:30 - 2015-10-01 08:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-25 13:30 - 2015-09-30 19:03 - 00001208 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-25 13:30 - 2015-09-30 19:03 - 00001208 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-25 13:30 - 2015-09-25 13:51 - 00000000 ____D C:\Users\frana\AppData\Local\Mozilla
2015-09-25 13:30 - 2015-09-25 13:30 - 00000000 ____D C:\Users\frana\AppData\Roaming\Mozilla
2015-09-25 13:28 - 2015-09-25 13:28 - 00000000 ____D C:\Users\frana\AppData\Roaming\ATI
2015-09-25 13:28 - 2015-09-25 13:28 - 00000000 ____D C:\Users\frana\AppData\Local\ATI
2015-09-25 13:28 - 2015-09-25 13:28 - 00000000 ____D C:\Users\frana\AppData\Local\AMD
2015-09-25 13:28 - 2015-09-25 13:28 - 00000000 ____D C:\ProgramData\ATI
2015-09-25 13:27 - 2015-09-25 13:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-09-25 13:27 - 2015-09-25 13:27 - 00000000 ____D C:\ProgramData\AMD
2015-09-25 13:27 - 2015-09-25 13:27 - 00000000 ____D C:\Program Files\ATI Technologies
2015-09-25 13:26 - 2015-09-25 13:27 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-09-25 13:25 - 2015-09-30 12:04 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-25 13:25 - 2015-09-26 07:46 - 00000000 ____D C:\Users\frana\AppData\Local\Google
2015-09-25 13:25 - 2015-09-25 13:25 - 47795680 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 39723504 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 30760944 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 27544560 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 25308656 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 22328800 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 21632992 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2015-09-25 13:25 - 2015-09-25 13:25 - 15727072 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 14312416 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 12062040 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atidxx64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 10191264 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 09191312 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdxc64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 08979760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 08865496 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 08009344 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 07575664 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdxc32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 07482560 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 06486000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 05076976 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 03471376 _____ C:\Windows\SysWOW64\atiumdva.cap
2015-09-25 13:25 - 2015-09-25 13:25 - 03437632 _____ C:\Windows\system32\atiumd6a.cap
2015-09-25 13:25 - 2015-09-25 13:25 - 01468224 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\aticfx64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 01257952 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 01213192 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 01196032 _____ C:\Windows\system32\amdocl_as64.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 01070592 _____ C:\Windows\system32\amdocl_ld64.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 01005552 _____ C:\Windows\SysWOW64\amdocl_as32.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00936928 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00936928 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00874480 _____ (AMD) C:\Windows\system32\coinst_15.20.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00833798 _____ C:\Windows\system32\amdicdxx.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00807424 _____ C:\Windows\SysWOW64\amdocl_ld32.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00737410 _____ C:\Windows\system32\atiicdxx.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00681456 _____ (AMD) C:\Windows\system32\atieclxx.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00675296 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2015-09-25 13:25 - 2015-09-25 13:25 - 00660928 _____ C:\Windows\SysWOW64\atiapfxx.blb
2015-09-25 13:25 - 2015-09-25 13:25 - 00660928 _____ C:\Windows\system32\atiapfxx.blb
2015-09-25 13:25 - 2015-09-25 13:25 - 00472832 _____ C:\Windows\system32\amdmiracast.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00452576 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00377312 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00341488 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00322868 _____ C:\Windows\system32\ativvaxy_vi.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00321200 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00256992 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00255808 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00250884 _____ C:\Windows\system32\ativvaxy_FJ.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00249088 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00243696 _____ C:\Windows\system32\clinfo.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00234420 _____ C:\Windows\system32\ativvaxy_cik.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00232752 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00213488 _____ C:\Windows\system32\amdgfxinfo64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00204952 _____ C:\Windows\SysWOW64\ativvsvl.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00204952 _____ C:\Windows\system32\ativvsvl.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00201184 _____ (AMD) C:\Windows\system32\atitmm64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00198640 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00170464 _____ C:\Windows\system32\atieah64.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00169152 _____ C:\Windows\system32\ativce03.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00167456 _____ C:\Windows\system32\amde31a.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00165360 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00162240 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00157144 _____ C:\Windows\SysWOW64\ativvsva.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00157144 _____ C:\Windows\system32\ativvsva.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00152560 _____ C:\Windows\SysWOW64\atieah32.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00152032 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00143344 _____ C:\Windows\system32\amdhdl64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00143048 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00136176 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00132080 _____ C:\Windows\SysWOW64\amdhdl32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00131592 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00122352 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00113880 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00111600 _____ C:\Windows\system32\hsa-thunk64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00111088 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00102384 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00100816 _____ C:\Windows\system32\ativce02.dat
2015-09-25 13:25 - 2015-09-25 13:25 - 00095216 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00089520 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00085472 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00082680 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00081160 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00073712 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00071152 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00069600 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00064496 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00062432 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00061408 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2015-09-25 13:25 - 2015-09-25 13:25 - 00059376 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00059360 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00052208 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00049632 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00039904 _____ (AMD) C:\Windows\system32\atimuixx.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00012784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00012784 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2015-09-25 13:25 - 2015-09-25 13:25 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-09-25 13:25 - 2015-09-25 13:25 - 00000000 ____D C:\Program Files\AMD
2015-09-25 13:25 - 2015-09-25 13:25 - 00000000 ____D C:\AMD
2015-09-25 13:25 - 2015-09-25 13:25 - 00000000 _____ C:\Windows\ativpsrm.bin
2015-09-25 13:24 - 2015-09-25 13:24 - 00103424 _____ (Advanced Micro Devices) C:\Windows\system32\DelayAPO.dll
2015-09-25 13:24 - 2015-09-25 13:24 - 00102912 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\AtihdWT6.sys
2015-09-25 13:24 - 2015-09-25 13:24 - 00017280 _____ () C:\Windows\system32\Drivers\ASACPI.sys
2015-09-25 13:23 - 2015-09-25 13:23 - 27898680 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA64.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 07235584 _____ (Dolby Laboratories) C:\Windows\system32\EEP64H.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 07235584 _____ (Dolby Laboratories) C:\Windows\system32\EEP64A.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 03309264 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIAPropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 02130448 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 02027184 _____ (Creative Technology Ltd.) C:\Windows\system32\VMAPO264.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 02012496 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaMicArrayAPO.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 01752904 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMAPO232.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 01560064 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrWia09b.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 01192784 _____ (VIA Technologies, Inc.) C:\Windows\system32\VIASysFx.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 01180496 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViaKaraokeApo.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 01031376 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00896344 _____ (Creative Technology Ltd.) C:\Windows\system32\VMAPO64.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00754760 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMAPO32.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00701136 _____ (VIA Technologies, Inc.) C:\Windows\system32\Drivers\viahduaa.sys
2015-09-25 13:23 - 2015-09-25 13:23 - 00678176 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00633904 _____ (Creative Technology Ltd.) C:\Windows\system32\VMTHX64.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00568304 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\VMTHX32.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00446224 _____ (Dolby Laboratories) C:\Windows\system32\EED64H.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00446224 _____ (Dolby Laboratories) C:\Windows\system32\EED64A.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00400504 _____ (Creative Technology Ltd.) C:\Windows\system32\VMWRP64.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00260120 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\Dts2APO.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00147224 _____ (Dolby Laboratories) C:\Windows\system32\EEL64A.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00147216 _____ (Dolby Laboratories) C:\Windows\system32\EEL64H.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00132248 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaKaraokePropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00130144 _____ (Dolby Laboratories) C:\Windows\system32\EEA64H.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00130144 _____ (Dolby Laboratories) C:\Windows\system32\EEA64A.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00104088 _____ (VIA Technologies,Inc.) C:\Windows\system32\ViaMicArrayPropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00101016 _____ (VIA Technologies, Inc.) C:\Windows\system32\Dts2PropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00094720 _____ (QSound Labs, Inc.) C:\Windows\system32\nQPropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00093712 _____ (QSound Labs, Inc.) C:\Windows\system32\nQAPO.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00084688 _____ (Dolby Laboratories) C:\Windows\system32\EEG64H.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00084688 _____ (Dolby Laboratories) C:\Windows\system32\EEG64A.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00080400 _____ (Windows (R) Codename Longhorn DDK provider) C:\Windows\system32\VtSrdAPO.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00067272 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPLD64.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00064152 _____ (TODO: <Company name>) C:\Windows\system32\PropPageExt.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00063144 _____ (Creative Technology Ltd.) C:\Windows\system32\VMPPCN64.DLL
2015-09-25 13:23 - 2015-09-25 13:23 - 00050176 _____ (Brother Industries, Ltd.) C:\Windows\system32\BrUsi09a.dll
2015-09-25 13:23 - 2015-09-25 13:23 - 00042192 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\VMfilt64.sys
2015-09-25 13:23 - 2015-09-25 13:23 - 00036504 _____ (VIA Technologies, Inc.) C:\Windows\system32\ViakaraokeSrv.exe
2015-09-25 13:23 - 2015-09-25 13:23 - 00000416 _____ C:\Windows\BRWMARK.INI
2015-09-25 13:23 - 2015-09-25 13:23 - 00000027 _____ C:\Windows\BRPP2KA.INI
2015-09-25 13:23 - 2015-09-25 13:23 - 00000000 ____D C:\Windows\system32\SRSLabs
2015-09-25 13:23 - 2015-09-25 13:23 - 00000000 ____D C:\Users\frana\AppData\Roaming\Macromedia
2015-09-25 13:23 - 2015-09-25 13:23 - 00000000 ____D C:\Program Files\VIA
2015-09-25 13:22 - 2015-09-25 13:22 - 00040684 _____ C:\Windows\system32\Drivers\AthrBT_0x31010000_ss01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001926 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0xf0.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001926 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0x21.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001926 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0x11.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001926 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001802 _____ C:\Windows\system32\Drivers\ramps_0x11020100_40_SS01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001802 _____ C:\Windows\system32\Drivers\ramps_0x11020100_40_nf01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001802 _____ C:\Windows\system32\Drivers\ramps_0x11020100_40.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001796 _____ C:\Windows\system32\Drivers\ramps_0x11020000_40.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_SS01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_LV01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0xf1.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0x22.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0x12.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001516 _____ C:\Windows\system32\Drivers\ramps_0x31010000_40_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001512 _____ C:\Windows\system32\Drivers\ramps_0x31010100_40_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001242 _____ C:\Windows\system32\Drivers\ramps_0x01020200_40_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001228 _____ C:\Windows\system32\Drivers\ramps_0x01020200_40_0x04.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001214 _____ C:\Windows\system32\Drivers\ramps_0x01020200_40_0x03.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001204 _____ C:\Windows\system32\Drivers\ramps_0x01020200_40_0x02.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001204 _____ C:\Windows\system32\Drivers\ramps_0x01020200_40.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001198 _____ C:\Windows\system32\Drivers\ramps_0x01020200_26.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00001192 _____ C:\Windows\system32\Drivers\ramps_0x01020200_26_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000296 _____ C:\Windows\system32\Drivers\ramps_0x01020201_40_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000278 _____ C:\Windows\system32\Drivers\ramps_0x01020201_40_0x04.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000264 _____ C:\Windows\system32\Drivers\ramps_0x01020201_40_0x03.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000264 _____ C:\Windows\system32\Drivers\ramps_0x01020201_40_0x02.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000264 _____ C:\Windows\system32\Drivers\ramps_0x01020201_40.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000264 _____ C:\Windows\system32\Drivers\ramps_0x01020201_26_0x01.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000264 _____ C:\Windows\system32\Drivers\ramps_0x01020201_26.dfu
2015-09-25 13:22 - 2015-09-25 13:22 - 00000000 ____D C:\Users\frana\AppData\Local\MicrosoftEdge
2015-09-25 13:22 - 2015-09-25 13:22 - 00000000 ____D C:\Program Files\Common Files\Atheros
2015-09-25 13:12 - 2015-09-28 20:53 - 00002362 _____ C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-25 13:12 - 2015-09-25 13:28 - 00000000 ___RD C:\Users\frana\OneDrive
2015-09-25 13:11 - 2015-09-25 13:11 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-09-25 13:10 - 2015-09-28 06:09 - 00000000 ____D C:\Users\frana\AppData\Local\Publishers
2015-09-25 13:09 - 2015-10-04 18:52 - 01762290 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-25 13:09 - 2015-10-02 19:35 - 00000000 ____D C:\Users\frana\AppData\Local\Packages
2015-09-25 13:09 - 2015-10-02 17:13 - 00000000 ____D C:\Users\frana
2015-09-25 13:09 - 2015-10-01 15:08 - 00000000 ____D C:\Users\frana\AppData\Roaming\Adobe
2015-09-25 13:09 - 2015-09-30 11:00 - 00000000 ____D C:\Users\frana\AppData\Local\VirtualStore
2015-09-25 13:09 - 2015-09-25 13:09 - 00016148 _____ C:\Windows\system32\DESKTOP-7PEJ7HM_defaultuser0_HistoryPrediction.bin
2015-09-25 13:09 - 2015-09-25 13:09 - 00000020 ___SH C:\Users\frana\ntuser.ini
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Šablony
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Soubory cookie
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Poslední
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Okolní tiskárny
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Okolní síť
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Nabídka Start
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Dokumenty
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Documents\Obrázky
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Documents\Hudba
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Documents\Filmy
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\Data aplikací
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 _SHDL C:\Users\frana\AppData\Local\Data aplikací
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 ___RD C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-25 13:09 - 2015-09-25 13:09 - 00000000 ____D C:\Users\frana\AppData\Local\TileDataLayer
2015-09-25 13:09 - 2015-07-10 13:04 - 00000000 __RSD C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-25 13:09 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-25 13:09 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-25 13:09 - 2015-07-10 13:04 - 00000000 ____D C:\Users\frana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-25 13:04 - 2015-09-25 13:04 - 00000000 ____D C:\Windows\CSC
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Public\Documents\Obrázky
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Public\Documents\Hudba
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Public\Documents\Filmy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Šablony
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Poslední
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Okolní síť
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Dokumenty
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\Data aplikací
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Šablony
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Plocha
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Nabídka Start
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Microsoft\Windows\Start Menu\Programy
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Dokumenty
2015-09-25 13:01 - 2015-09-25 13:01 - 00000000 _SHDL C:\ProgramData\Data aplikací
2015-09-25 12:59 - 2015-09-25 12:59 - 00000000 __SHD C:\Recovery
2015-09-25 12:59 - 2015-07-10 12:59 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2015-09-25 12:57 - 2015-09-25 12:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-09-23 11:31 - 2015-06-12 04:00 - 00197616 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys
2015-09-22 18:14 - 2015-09-22 18:14 - 00017568 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\gtkdrv.sys
2015-09-14 20:52 - 2015-09-14 20:52 - 02843384 _____ (O&O Software GmbH) C:\Windows\system32\ooscrsav.scr
2015-09-14 20:52 - 2015-09-14 20:52 - 00543992 _____ (O&O Software GmbH) C:\Windows\system32\oodssrs.dll
2015-09-14 20:52 - 2015-09-14 20:52 - 00240376 _____ (O&O Software GmbH) C:\Windows\system32\oodbs.exe
2015-09-14 20:52 - 2015-09-14 20:52 - 00010488 _____ (O&O Software GmbH) C:\Windows\system32\oodbsrs.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00627288 _____ (Microsoft Corporation) C:\Windows\system32\msvcp140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00430264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00381128 _____ (Microsoft Corporation) C:\Windows\system32\vccorlib140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00325232 _____ (Microsoft Corporation) C:\Windows\system32\concrt140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00257736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vccorlib140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00235632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\concrt140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00080984 _____ (Microsoft Corporation) C:\Windows\system32\vcruntime140.dll
2015-09-09 23:55 - 2015-09-09 23:55 - 00077400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vcruntime140.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-05 07:30 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\sru
2015-10-05 06:29 - 2015-07-10 14:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-04 19:12 - 2015-07-10 11:05 - 01572864 ___SH C:\Windows\system32\config\BBI
2015-10-04 18:52 - 2015-07-10 18:01 - 00745406 _____ C:\Windows\system32\perfh005.dat
2015-10-04 18:52 - 2015-07-10 18:01 - 00149344 _____ C:\Windows\system32\perfc005.dat
2015-10-04 18:47 - 2015-07-10 14:20 - 00340248 _____ C:\Windows\system32\FNTCACHE.DAT
2015-10-04 12:22 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\GroupPolicy
2015-10-04 11:10 - 2015-07-10 15:19 - 00000000 ____D C:\Windows\DigitalLocker
2015-10-04 07:06 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\AppReadiness
2015-10-03 19:05 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\Performance
2015-10-03 17:40 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\rescache
2015-10-02 11:32 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\TAPI
2015-10-02 06:20 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ___SD C:\Windows\SysWOW64\F12
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ___SD C:\Windows\system32\F12
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ___RD C:\Windows\PurchaseDialog
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\appraiser
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\Provisioning
2015-10-01 11:11 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\L2Schemas
2015-10-01 10:43 - 2015-07-10 12:55 - 00000000 ____D C:\Windows\CbsTemp
2015-10-01 10:36 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\LiveKernelReports
2015-09-30 09:21 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\Registration
2015-09-29 19:04 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\System
2015-09-29 06:51 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\NDF
2015-09-28 08:58 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2015-09-26 07:00 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\SysWOW64\MUI
2015-09-26 07:00 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\MUI
2015-09-26 06:31 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\appcompat
2015-09-25 20:26 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\Cursors
2015-09-25 19:54 - 2015-07-10 13:04 - 00000853 _____ C:\Windows\system32\Drivers\etc\hosts.old
2015-09-25 19:28 - 2015-07-10 18:04 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-25 19:28 - 2015-07-10 13:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2015-09-25 19:28 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-25 19:28 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-25 19:28 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\SysWOW64\oobe
2015-09-25 19:28 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\oobe
2015-09-25 19:28 - 2015-07-10 11:05 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-09-25 19:28 - 2015-07-10 11:05 - 00000000 ____D C:\Windows\system32\Dism
2015-09-25 13:54 - 2015-07-10 13:04 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-09-25 13:26 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\restore
2015-09-25 13:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Windows\PrintDialog
2015-09-25 13:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Windows\MiracastView
2015-09-25 13:04 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\spool
2015-09-25 13:01 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows NT
2015-09-25 13:01 - 2015-07-10 11:05 - 00000000 __RHD C:\Users\Default
2015-09-25 13:00 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-09-25 12:59 - 2015-07-10 13:04 - 00000000 ____D C:\Windows\system32\Recovery
2015-09-25 12:58 - 2015-07-10 11:05 - 00000000 ____D C:\Windows\system32\Sysprep

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-09-25 12:56

==================== End of FRST.txt ============================

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod jaro3 » 05 říj 2015 10:05

Odinstaluj:
IObit Malware Fighter
Advanced SystemCare Ultimate 8
TrojanKiller
Spyhunter


Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
HKLM-x32\...\RunOnce: [InstallShieldSetup] => "C:\PROGRA~2\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /reboot /z
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0592-6373-11e5-9bc2-806e6f6e6963} - "M:\Autorun.exe"
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0594-6373-11e5-9bc2-806e6f6e6963} - "O:\WD SmartWare.exe" autoplay=true
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
C:\Users\frana\Downloads\Malwarebytes Anti-Malware Premium 2.1.8.1057 Multilingual + KeyGen by FFF
C:\Users\frana\Downloads\Piriform Speccy Professional 1.28.708 Final Incl. Crack [ATOM]
C:\Users\frana\Downloads\Piriform Speccy Professional v1.28.709 Multilingual Incl Keymaker-CORE [TorDigger]
C:\Users\frana\Downloads\SUPERAntiSpyware Professional 6.0.1204 Multilingual Keys + Keymaker [4realtorrentz].zip
C:\ProgramData\install_clap
C:\Windows\Tasks\ImCleanDisabled
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.

V možnostech složky si povol zobrazování skrytých souborů a složek+ odškrtni zatržítko skrýt chráněné soubory operačního systému

Toto otestuj na Virustotal
C:\Windows\SECOH-QAD.dll

Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Nebo na:
http://www.virscan.org/
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 05 říj 2015 20:11

Start
CloseProcesses:
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
HKLM-x32\...\RunOnce: [InstallShieldSetup] => "C:\PROGRA~2\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /reboot /z
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0592-6373-11e5-9bc2-806e6f6e6963} - "M:\Autorun.exe"
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0594-6373-11e5-9bc2-806e6f6e6963} - "O:\WD SmartWare.exe" autoplay=true
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
C:\Users\frana\Downloads\Malwarebytes Anti-Malware Premium 2.1.8.1057 Multilingual + KeyGen by FFF
C:\Users\frana\Downloads\Piriform Speccy Professional 1.28.708 Final Incl. Crack [ATOM]
C:\Users\frana\Downloads\Piriform Speccy Professional v1.28.709 Multilingual Incl Keymaker-CORE [TorDigger]
C:\Users\frana\Downloads\SUPERAntiSpyware Professional 6.0.1204 Multilingual Keys + Keymaker [4realtorrentz].zip
C:\ProgramData\install_clap
C:\Windows\Tasks\ImCleanDisabled
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 06 říj 2015 07:44

Tohle nějak nechápu : Klikni vpravo od okénka na Vybrat a v Exploreru najdi požadovaný soubor v Tvém PC. Označ ho myší a klikni na Otevřít , poté klikni na Send File. Pokud už byl soubor testován , objeví se okno ve kterém klikni na Reanalyze. Soubor se začne postupně testovat více antivirovými programy. Až skončí test posledního antiviru , objeví se nahoře result a červeně počet nákaz , např. 0/43 , nebo 1/43. Pak zkopíruj myší odkaz na tuto stránku a vlož ji do svého příspěvku.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod jaro3 » 06 říj 2015 09:58

přečti si znovu návod na script FRST , nic si neudělal. Přečti znovu radu ohledně virustotal , je to tam přeci podrobně popsáno.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 06 říj 2015 14:06

Jdu to zkusit ale nějak mi to nejde.

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 06 říj 2015 14:11

Já nevím jestli to dělám zprávně :-(

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 06 říj 2015 14:12

URL: http://malwaretips.com/blogs/ads-by-cat ... u-removal/
Detection ratio: 0 / 65
Analysis date: 2015-10-06 12:10:03 UTC ( 0 minut ago )
0 0
Analysis
Additional information
Comments 0
Votes
URL Scanner Result
CloudStat Clean site
ADMINUSLabs Clean site
AegisLab WebGuard Clean site
AlienVault Clean site
Antiy-AVL Clean site
Avira Clean site
Baidu-International Clean site
BitDefender Clean site
Blueliv Clean site
C-SIRT Clean site
CLEAN MX Clean site
CRDF Clean site
Comodo Site Inspector Clean site
CyberCrime Clean site
Dr.Web Clean site
ESET Clean site
Emsisoft Clean site
Fortinet Clean site
FraudScore Clean site
FraudSense Clean site
G-Data Clean site
Google Safebrowsing Clean site
K7AntiVirus Clean site
Kaspersky Clean site
Malc0de Database Clean site
Malekal Clean site
Malware Domain Blocklist Clean site
MalwareDomainList Clean site
MalwarePatrol Clean site
Malwarebytes hpHosts Clean site
Malwared Clean site
OpenPhish Clean site
Opera Clean site
PalevoTracker Clean site
ParetoLogic Clean site
Phishtank Clean site
Quttera Clean site
Rising Clean site
SCUMWARE.org Clean site
SecureBrain Clean site
Spam404 Clean site
SpyEyeTracker Clean site
Sucuri SiteCheck Clean site
Tencent Clean site
ThreatHive Clean site
Trustwave Clean site
VX Vault Clean site
Web Security Guard Clean site
Websense ThreatSeeker Clean site
Webutation Clean site
Wepawet Clean site
Yandex Safebrowsing Clean site
ZCloudsec Clean site
ZDB Zeus Clean site
ZeroCERT Clean site
Zerofox Clean site
ZeusTracker Clean site
malwares.com URL checker Clean site
zvelo Clean site
AutoShun Unrated site
Netcraft Unrated site
PhishLabs Unrated site
Sophos Unrated site
StopBadware Unrated site
URLQuery Unrated site

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod jaro3 » 07 říj 2015 10:04

Ještě zkus ten script v FRST , to co si dával je jen script , potřebuji to dát smazat.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 07 říj 2015 19:10

Additional scan result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by frana (2015-10-07 19:01:04)
Running from C:\Users\frana\Downloads
Windows 10 Enterprise (X64) (2015-09-25 11:08:29)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1404004499-2870367066-3409248046-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1404004499-2870367066-3409248046-503 - Limited - Disabled)
frana (S-1-5-21-1404004499-2870367066-3409248046-1001 - Administrator - Enabled) => C:\Users\frana
Guest (S-1-5-21-1404004499-2870367066-3409248046-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adblock Plus for IE (32-bit and 64-bit) (HKLM\...\{CB320215-F4BD-40FD-A209-62B131DA1B82}) (Version: 99.9 - Eyeo GmbH)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0E0F06755100}) (Version: 15.006.30060 - Adobe Systems Incorporated)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
AIDA64 Extreme v4.60 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 4.60 - FinalWire Ltd.)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
Ashampoo Burning Studio 15 v.15.0.0 (HKLM-x32\...\{91B33C97-5B38-0A92-D04A-A0F26F3F87D4}_is1) (Version: 15.0.0 - Ashampoo GmbH & Co. KG)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.69.1079 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.10 - Piriform)
CyberLink PowerDVD 15 (HKLM-x32\...\{DE85B8F3-D088-4D6E-A970-EE0BC7883A66}) (Version: 15.0.1510.58 - CyberLink Corp.)
CyberLink PowerDVD 15.0.1510.58 - odinstalovat češtinu (HKLM-x32\...\CyberLink PowerDVD 15.0.1510.58) (Version: - Michellin & Cehos)
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.4.0.0377 - Disc Soft Ltd)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version: - )
Freemake Video Converter verze 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.101 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.246 - SurfRight B.V.)
Horloger 1.0 Final (HKLM-x32\...\Horloger 1.0 Final) (Version: - )
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.3.0.5 - IObit)
Malwarebytes Anti-Malware verze 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MediaInfo 0.7.78 (HKLM\...\MediaInfo) (Version: 0.7.78 - MediaArea.net)
Metric Collection SDK 35 (x32 Version: 1.2.0010.00 - Lenovo Group Limited) Hidden
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProplusRetail - cs-cz) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProplusRetail - en-us) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Project Professional 2016 - cs-cz (HKLM\...\ProjectProRetail - cs-cz) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Visio Professional 2016 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Mozilla Firefox 41.0.1 (x86 cs) (HKLM-x32\...\Mozilla Firefox 41.0.1 (x86 cs)) (Version: 41.0.1 - Mozilla)
MPC-HC 1.7.8 (HKLM-x32\...\{2624B969-7135-4EB1-B0F6-2D8C397B45F7}_is1) (Version: 1.7.8 - MPC-HC Team)
Nero 2016 (HKLM-x32\...\{4297E807-5633-466A-8AC0-5AC48D310471}) (Version: 17.0.02000 - Nero AG)
Nero Info (HKLM-x32\...\{F030BFE8-8476-4C08-A553-233DE80A2BE1}) (Version: 16.0.2000 - Nero AG)
O&O Defrag Professional (HKLM\...\{6F9CDC3F-27D8-4A38-B81D-7E2DE3AF8434}) (Version: 19.0.87 - O&O Software GmbH)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Opera Stable 32.0.1948.69 (HKLM-x32\...\Opera 32.0.1948.69) (Version: 32.0.1948.69 - Opera Software)
Prerequisite installer (x32 Version: 17.0.0002 - Nero AG) Hidden
Revo Uninstaller Pro 3.1.4 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.4 - VS Revo Group, Ltd.)
Seznam Software (HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\SeznamInstall) (Version: - Seznam.cz)
Smart Defrag 4 (HKLM-x32\...\Smart Defrag 4_is1) (Version: 4.2 - IObit)
Stashimi Stub Installer (x32 Version: 18.001.1 - Nero AG) Hidden
The KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 3.5.0.77 - KMP Media co., Ltd)
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.5.0.0 - )
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM-x32\...\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WinRAR 5.30 beta 2 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.2 - win.rar GmbH)
Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2014.3 - URSoft, Inc.)
Zoner Photo Studio 18 (HKLM\...\ZonerPhotoStudio18_CZ_is1) (Version: 18.0.1.1 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

01-10-2015 18:16:53 Kontrolní bod aplikace HitmanPro
03-10-2015 18:04:46 Revo Uninstaller Pro's restore point - SHAREit
04-10-2015 18:42:01 Installed PowerProducer
05-10-2015 19:48:52 Revo Uninstaller Pro's restore point - SpyHunter
06-10-2015 20:48:09 Installed Adblock Plus for IE (32-bit and 64-bit)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-04 12:03 - 2015-10-04 12:03 - 00000753 ____A C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3B9F5CA2-A924-4243-A7E3-E678C2A19411} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2015-10-02] (Microsoft Corporation)
Task: {40C4C1E8-AA38-4976-A734-2B005A4D9A4C} - System32\Tasks\SmartDefrag4_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe [2015-03-03] (IObit)
Task: {461DFFDA-63AF-4382-ABF6-0D1A96894F2F} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {4763B476-757F-4CAA-9484-7EAF65F29832} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2015-10-02] (Microsoft Corporation)
Task: {49B62C78-EFFC-41FF-BCB1-A65A2CBF7A29} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {5EA1A59A-08E0-4277-86D2-45C21C27DEF4} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-09-26] (Microsoft Corporation)
Task: {6518E485-1592-409E-9970-CBADD595B23D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-09-27] (AVAST Software)
Task: {742AD200-F00C-4616-B6CC-2D7F76CE8557} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-06] (Google Inc.)
Task: {8D7D3D8C-F2C3-45A2-AF73-8294B541D633} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-09-16] (Piriform Ltd)
Task: {950577CC-2761-4EE5-BF41-F56830980522} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {9BF9609A-E424-4B04-AD06-8335162E98A9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-06] (Google Inc.)
Task: {AD0432E5-C844-4972-8171-C31868A5F8C5} - System32\Tasks\ASCU8_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\Monitor.exe
Task: {B9265F71-2E15-41C4-AFCE-CDC8CB38F328} - System32\Tasks\Uninstaller_SkipUac_frana => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-05-20] (IObit)
Task: {C19046BB-4C80-4682-9058-54107DCAA7C4} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe [2015-06-04] (Nero AG)
Task: {C7F83584-B816-4C90-BA0A-A60152DDB068} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-09-26] (Microsoft Corporation)
Task: {E8CB1454-CA9E-4A77-AD47-06478AF12A5B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-10-04] (Adobe Systems Incorporated)
Task: {F68C1C84-AE89-4B3F-80D9-CD378C5DC723} - System32\Tasks\ASCU8_SkipUac_frana => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASC.exe
Task: {FE55CCE0-819A-4958-AB2B-65F3D5C8D163} - System32\Tasks\Opera scheduled Autoupdate 1443195752 => C:\Program Files (x86)\Opera\launcher.exe [2015-09-25] (Opera Software)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\ASCU8_SkipUac_frana.job => C:\Program Files (x86)\IObit\Advanced SystemCare Ultimate 8\ASC.exe
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Uninstaller_SkipUac_frana.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe

==================== Loaded Modules (Whitelisted) ==============

2015-09-25 18:54 - 2015-07-15 04:04 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll
2015-09-25 18:54 - 2015-08-11 11:14 - 00404480 _____ () C:\Windows\System32\diagtrack_wininternal.dll
2015-10-02 05:59 - 2015-09-26 22:46 - 00161448 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
2015-10-01 05:28 - 2015-09-17 08:48 - 02494712 _____ () C:\Windows\system32\CoreUIComponents.dll
2015-10-01 05:28 - 2015-09-17 08:48 - 02494712 _____ () C:\Windows\System32\CoreUIComponents.dll
2015-10-01 05:28 - 2015-09-17 07:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-01 05:29 - 2015-09-17 07:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 05:27 - 2015-09-17 07:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 05:28 - 2015-09-17 07:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 05:28 - 2015-09-17 07:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-08-21 22:09 - 2015-08-21 22:09 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2015-09-27 19:27 - 2015-09-27 19:27 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-09-27 19:27 - 2015-09-27 19:27 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-10-07 12:39 - 2015-10-07 12:39 - 02967040 _____ () C:\Program Files\AVAST Software\Avast\defs\15100701\algo.dll
2015-09-25 19:36 - 2014-10-16 10:26 - 00622880 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2015-09-27 19:27 - 2015-09-27 19:27 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-09-26 06:26 - 2013-01-15 18:48 - 00348992 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2015-09-26 06:26 - 2013-01-15 18:48 - 00183616 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2015-09-26 06:26 - 2013-01-15 18:48 - 00051008 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2015-03-17 02:17 - 2015-03-17 02:17 - 00010240 _____ () C:\Program Files (x86)\Adobe\Acrobat 2015\Acrobat\locale\cs_cz\AcroTray.cze

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\Control Panel\Desktop\\Wallpaper -> D:\Fotky\blue-dreams-fantasy-girl-1680x1050.jpg
DNS Servers: 213.46.172.36 - 213.46.172.37
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "O&O Defrag Tray.lnk"
HKLM\...\StartupApproved\Run: => "OODefragTray"
HKLM\...\StartupApproved\Run32: => "IObit Malware Fighter"
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\StartupApproved\Run: => "Advanced SystemCare Ultimate"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{51924C6E-0C67-441C-B100-93F18699B1A8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C636DAB8-D270-4A51-BB18-D267942F496B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{28B01CA3-2DAF-4DAC-8822-B4B56E18B026}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{634B8D52-94F4-4C5A-87A0-DCEEA84D2E18}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{84AF8AFD-2721-4403-B4CA-998A16AB8FBC}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{FD259324-B8A3-4BE9-8F3D-EDEE0C29687C}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{A6D28F73-7094-4609-A356-4DADD070887F}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{1ACC3BD6-6740-4D5E-A83D-25F612E44A7F}C:\users\frana\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\frana\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{399E6D28-9F8E-4898-9759-5FB9D378AEF4}C:\users\frana\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\frana\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{4253C1A3-47E3-442F-B470-E01523F4E59D}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD.exe
FirewallRules: [{68A42B61-CB59-412F-AD16-C294A140CAAE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Kernel\DMS\CLMSServerPDVD15.exe
FirewallRules: [{A83CCA78-A0B1-4A24-AAAC-0138D770DE22}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
FirewallRules: [{12EA8678-27CE-48AA-B7BC-ED4E0E24AFDE}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVDMovie.exe
FirewallRules: [{EFE10488-CCF2-4C79-9215-853D78350C43}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVD Cinema\PowerDVDCinema.exe
FirewallRules: [{A2A81D37-CBBF-43FA-9548-304EA2E97F16}] => (Allow) C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\StartNBR.exe
FirewallRules: [{953CB403-02D2-4FB5-B14C-5DA1F7BABD00}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe
FirewallRules: [{3A2F8A36-D859-4B92-A357-713A91EA9F2F}] => (Allow) C:\Program Files (x86)\Nero\Nero 2016\Nero Burning ROM\nero.exe
FirewallRules: [{9B3E05AB-0B14-40E0-B7BE-1E56289D9664}] => (Allow) C:\Program Files\Zoner\Photo Studio 18\Program32\MediaServer.exe
FirewallRules: [{A3575C26-5147-479A-A425-CB2C4FB2CF4A}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============

Name: WD SES Device USB Device
Description: WD SES Device USB Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: WD SES Device USB Device
Description: WD SES Device USB Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/07/2015 06:57:10 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest1 se nezdařilo. Chyba v souboru manifestu nebo zásad C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest2 na řádku C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest3.
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest.
Součást 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_3bccb1ff6bcd1849.manifest.

Error: (10/07/2015 05:19:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchUI.exe verze 10.0.10240.16515 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: f08

Čas spuštění: 01d10112eb131d60

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

ID hlášení: cb355ca2-6d06-11e5-9c12-e0cb4eb8b9b1

Úplný název balíčku s chybou: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy

ID aplikace související s balíčkem s chybou: CortanaUI

Error: (10/07/2015 05:19:24 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: DESKTOP-7PEJ7HM)
Description: Balíček Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy+CortanaUI se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (10/07/2015 04:55:22 PM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (4692) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (10/07/2015 04:55:22 PM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (4692) Pokus o vytvoření souboru C:\Windows\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (10/07/2015 04:55:12 PM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (4692) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (10/07/2015 04:55:12 PM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (4692) Pokus o vytvoření souboru C:\Windows\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (10/07/2015 04:55:01 PM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (4692) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032

Error: (10/07/2015 04:55:01 PM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (4692) Pokus o vytvoření souboru C:\Windows\system32\edbtmp.log selhal. Došlo k systémové chybě 5 (0x00000005): Přístup byl odepřen. . Operace vytvoření souboru selže a dojde k chybě -1032 (0xfffffbf8).

Error: (10/07/2015 04:54:51 PM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (4692) Nový soubor protokolu se nedá vytvořit, protože databáze nemůže zapisovat na jednotku protokolu. Jednotka může být jen pro čtení, špatně nakonfigurovaná nebo poškozená nebo na ní nemusí být dost místa. Chyba: -1032


System errors:
=============
Error: (10/07/2015 05:51:57 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Zjišťování interaktivních služeb byla ukončena s následující chybou:
%%1

Error: (10/07/2015 05:51:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Zjišťování interaktivních služeb byla ukončena s následující chybou:
%%1

Error: (10/07/2015 05:13:28 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba Pomocník pro připojení k síti závisí na službě Pomocná služba protokolu IP, která neuspěla při spuštění v důsledku následující chyby:
%%1058

Error: (10/07/2015 05:13:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Advanced SystemCare Service 8 neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (10/07/2015 05:13:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba AdvancedSystemCareAntivirus neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (10/07/2015 05:13:15 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: 0x0000009f (0x0000000000000003, 0xffffe00186000600, 0xfffff800e6ff2ad0, 0xffffe0018a9e6010)C:\Windows\MEMORY.DMP100715-18062-01

Error: (10/07/2015 05:13:14 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (13:58:20, ‎07.‎10.‎2015) bylo neočekávané.

Error: (10/07/2015 01:10:31 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-7PEJ7HM)
Description: specifické pro aplikaciMístníAktivace{9E175B6D-F52A-11D8-B9A5-505054503030}{9E175B9C-F52A-11D8-B9A5-505054503030}DESKTOP-7PEJ7HMfranaS-1-5-21-1404004499-2870367066-3409248046-1001LocalHost (pomocí LRPC)Není k dispoziciS-1-15-2-761974426-54629027-2233664358-314040001-2544375812-431583167-2906787342

Error: (10/07/2015 08:40:32 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DESKTOP-7PEJ7HM)
Description: 0x8000002a117\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-1404004499-2870367066-3409248046-1001-0-ntuser.dat

Error: (10/07/2015 08:40:20 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: DESKTOP-7PEJ7HM)
Description: 0x8000002a117\??\C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\S-1-5-21-1404004499-2870367066-3409248046-1001-0-ntuser.dat


CodeIntegrity:
===================================
Date: 2015-10-02 08:20:28.432
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements.

Date: 2015-10-02 07:59:05.120
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements.

Date: 2015-10-02 07:50:27.045
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files (x86)\Elex-tech\YAC\iSafeSrvMon64.dll that did not meet the Windows signing level requirements.


==================== Memory info ===========================

Processor: AMD Phenom(tm) II X4 955 Processor
Percentage of memory in use: 26%
Total physical RAM: 6143.17 MB
Available physical RAM: 4521.59 MB
Total Virtual: 7167.17 MB
Available Virtual: 5304.16 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:298.09 GB) (Free:231.49 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:745.21 GB) (Free:637.33 GB) NTFS
Drive e: (Svazek I) (Fixed) (Total:1862.36 GB) (Free:785.96 GB) NTFS
Drive f: (Svazek (J:)) (Fixed) (Total:1396.61 GB) (Free:533.61 GB) NTFS
Drive n: (WD SmartWare) (CDROM) (Total:0.65 GB) (Free:0 GB) UDF
Drive o: (WD SmartWare) (CDROM) (Total:0.63 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 745.2 GB) (Disk ID: F216BFEA)
Partition 1: (Active) - (Size=745.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: B062B062)
Partition 1: (Active) - (Size=298.1 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (Size: 1396.6 GB) (Disk ID: 570E0F9E)
Partition 1: (Active) - (Size=1396.6 GB) - (Type=07 NTFS)

========================================================
Disk: 4 (Size: 1862.4 GB) (Disk ID: 04579685)
Partition 1: (Not Active) - (Size=1862.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod jaro3 » 07 říj 2015 19:22

Tak ještě jednou:

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
Start
CloseProcesses:
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
HKLM-x32\...\RunOnce: [InstallShieldSetup] => "C:\PROGRA~2\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /reboot /z
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0592-6373-11e5-9bc2-806e6f6e6963} - "M:\Autorun.exe"
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0594-6373-11e5-9bc2-806e6f6e6963} - "O:\WD SmartWare.exe" autoplay=true
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
C:\Users\frana\Downloads\Malwarebytes Anti-Malware Premium 2.1.8.1057 Multilingual + KeyGen by FFF
C:\Users\frana\Downloads\Piriform Speccy Professional 1.28.708 Final Incl. Crack [ATOM]
C:\Users\frana\Downloads\Piriform Speccy Professional v1.28.709 Multilingual Incl Keymaker-CORE [TorDigger]
C:\Users\frana\Downloads\SUPERAntiSpyware Professional 6.0.1204 Multilingual Keys + Keymaker [4realtorrentz].zip
C:\ProgramData\install_clap
C:\Windows\Tasks\ImCleanDisabled
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

frana09
Level 1.5
Level 1.5
Příspěvky: 135
Registrován: duben 11
Bydliště: Praha
Pohlaví: Muž
Stav:
Offline

Re: kontrola logu - poblázněné prohlížeče

Příspěvekod frana09 » 07 říj 2015 20:05

Fix result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by frana (2015-10-07 19:56:48) Run:1
Running from C:\Users\frana\Desktop
Loaded Profiles: frana (Available Profiles: frana)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
Start
CloseProcesses:
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51
HKLM-x32\...\RunOnce: [InstallShieldSetup] => "C:\PROGRA~2\InstallShield Installation Information\{B7A0CE06-068E-11D6-97FD-0050BACBF861}\Setup.exe" /reboot /z
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0592-6373-11e5-9bc2-806e6f6e6963} - "M:\Autorun.exe"
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\...\MountPoints2: {f27b0594-6373-11e5-9bc2-806e6f6e6963} - "O:\WD SmartWare.exe" autoplay=true
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1404004499-2870367066-3409248046-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
C:\Users\frana\Downloads\Malwarebytes Anti-Malware Premium 2.1.8.1057 Multilingual + KeyGen by FFF
C:\Users\frana\Downloads\Piriform Speccy Professional 1.28.708 Final Incl. Crack [ATOM]
C:\Users\frana\Downloads\Piriform Speccy Professional v1.28.709 Multilingual Incl Keymaker-CORE [TorDigger]
C:\Users\frana\Downloads\SUPERAntiSpyware Professional 6.0.1204 Multilingual Keys + Keymaker [4realtorrentz].zip
C:\ProgramData\install_clap
C:\Windows\Tasks\ImCleanDisabled
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
EmptyTemp:
End
*****************

Processes closed successfully.
Processes closed successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\ProgramData\TEMP => ":1CE11B51" ADS removed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\InstallShieldSetup => value not found.
HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value removed successfully
"HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f27b0592-6373-11e5-9bc2-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{f27b0592-6373-11e5-9bc2-806e6f6e6963} => key not found.
"HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f27b0594-6373-11e5-9bc2-806e6f6e6963}" => key removed successfully
HKCR\CLSID\{f27b0594-6373-11e5-9bc2-806e6f6e6963} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0191A6B0-1154-4C22-9182-23A95BBE92D9} => key not found.
"HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
"HKU\S-1-5-21-1404004499-2870367066-3409248046-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0191A6B0-1154-4C22-9182-23A95BBE92D9}" => key removed successfully
HKCR\CLSID\{0191A6B0-1154-4C22-9182-23A95BBE92D9} => key not found.
C:\Users\frana\Downloads\Malwarebytes Anti-Malware Premium 2.1.8.1057 Multilingual + KeyGen by FFF => moved successfully
C:\Users\frana\Downloads\Piriform Speccy Professional 1.28.708 Final Incl. Crack [ATOM] => moved successfully
C:\Users\frana\Downloads\Piriform Speccy Professional v1.28.709 Multilingual Incl Keymaker-CORE [TorDigger] => moved successfully
C:\Users\frana\Downloads\SUPERAntiSpyware Professional 6.0.1204 Multilingual Keys + Keymaker [4realtorrentz].zip => moved successfully
C:\ProgramData\install_clap => moved successfully
C:\Windows\Tasks\ImCleanDisabled => moved successfully
"C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job" => File/Folder not found.
"C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job" => File/Folder not found.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
EmptyTemp: => 568.4 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 19:58:46 ====


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 92 hostů