COM surogate Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: COM surogate  Vyřešeno

Příspěvekod Orcus » 19 úno 2016 22:51

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka).
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva" a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

====================================================

Stáhni
Zoek.exe

a ulož si ho na plochu.
Zavři všechny ostatní programy, okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
- pozor, náběh programu může trvat déle.

Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
emptyclsid;
iedefaults;
FFdefaults;
CHRdefaults;
emptyalltemp;
resethosts;


Klikni na Run Script
Program provede sken, opravu, sken i oprava může trvat i více minut, je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .

Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů, jinak se sám ukládá do:
C:\zoek-results.log
Zkopíruj sem celý obsah toho logu.

====================================================

Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Reklama
Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 24 úno 2016 19:21

RogueKiller V11.0.12.0 (x64) [Feb 15 2016] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/software/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 10 (10.0.10586) 64 bits version
Spuštěno : Normální režim
Uživatel : Adam [Práva správce]
Started from : C:\Users\Adam\Desktop\RogueKillerX64.exe
Mód : Smazat -- Datum : 02/24/2016 19:20:37

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 6 ¤¤¤
[PUP] (X64) HKEY_LOCAL_MACHINE\Software\Partner -> Smazáno
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WUDFRd (system32\drivers\WudfRd.sys) -> Smazáno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 ([X]) -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.138 ([X]) -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2d73bac2-2453-4f32-8952-edc3ddea458f} | DhcpNameServer : 10.0.0.138 ([X]) -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{2d73bac2-2453-4f32-8952-edc3ddea458f} | DhcpNameServer : 10.0.0.138 ([X]) -> Nahrazeno ()

¤¤¤ Úlohy : 0 ¤¤¤

¤¤¤ Soubory : 1 ¤¤¤
[PUP][Složka] C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} -> Smazáno
[PUP][Soubor] C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}\{D3742F82-1C1A-4DCC-ABBD-0E831C0185CC}.msi -> Smazáno

¤¤¤ Soubor HOSTS : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 2 ¤¤¤
[FIREFX:Addon] q2tciqdz.default : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> Smazáno
[PUM.HomePage][FIREFX:Config] q2tciqdz.default : user_pref("browser.startup.homepage", "http://www.seznam.cz/"); -> Nahrazeno (about:home)

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: SAMSUNG HD403LJ +++++
--- User ---
[MBR] cbf97b3167d56ef960162cef9635dbea
[BSP] 76553aaf94bcb12534c56f9985a03b4c : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 381551 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Samsung SSD 840 EVO 120GB +++++
--- User ---
[MBR] fba6d7e9db2fe0792639df3c48c315c3
[BSP] 92d9f6df062c9d480587791b57b2402a : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114471 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: ST1000DM003-1CH162 +++++
--- User ---
[MBR] 234444136e6447582966f3e8178cf13e
[BSP] 8a9e76a833893ad549383040f1ceede7 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 317952 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 651167744 | Size: 317952 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1302333440 | Size: 317963 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 24 úno 2016 19:37

Zoek.exe v5.0.0.1 Updated 31-December-2015
Tool run by Adam on st 24.02.2016 at 19:22:53,16.
Microsoft Windows 10 Pro 10.0.10586 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Adam\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

24.2.2016 19:23:18 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\ASUS deleted successfully
C:\PROGRA~2\VideoLAN deleted successfully
C:\Program Files\Google deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\Users\DefaultAppPool\AppData\LocalLow deleted successfully
C:\Users\Adam\AppData\Local\ActiveSync deleted successfully
C:\Users\Adam\AppData\Local\EmieSiteList deleted successfully
C:\Users\Adam\AppData\Local\EmieUserList deleted successfully
C:\Users\Adam\AppData\Local\Opera Software deleted successfully
C:\Users\Adam\AppData\Local\PeerDistRepub deleted successfully
C:\Users\Adam\AppData\Local\Skype deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Maps deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-3171289305-1862197294-184807748-1000\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\q2tciqdz.default\prefs.js:
user_pref("browser.startup.homepage", "about:home"about:home);

Added to C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\q2tciqdz.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\ASUS not found
C:\PROGRA~2\VideoLAN not found
C:\PROGRA~2\SystemRequirementsLab deleted
C:\Users\Adam\.android deleted
C:\PROGRA~2\Truhlar NPmypict.tmp deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Adam\AppData\Local\Unity deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\Adam\AppData\LocalLow\Unity deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\q2tciqdz.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\q2tciqdz.default
6FE651F6E3025AD51CC1D54913AEEADC - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll - Shockwave Flash
3181BF855B17B3765330573B9659F05D - C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\npGatewayNpapi.dll - Skype Web Plugin
FF892B8E98B4E7BA87063A8AD8E2219E - C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\npGatewayNpapi-x64.dll - Skype Web Plugin


==== Chromium Look ======================

Angry Birds - Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj
AdBlock - Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02

==== Reset Google Chrome ======================

C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Preferences was reset successfully
C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Secure Preferences was reset successfully
C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Web Data was reset successfully
C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\UnityWebPlayer deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Adam\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Adam\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Adam\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Adam\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Adam\AppData\Local\Mozilla\Firefox\Profiles\q2tciqdz.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=62 folders=51 62078983 bytes)

==== Empty Temp Folders ======================

C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Adam\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 24.02.2016 at 19:34:58,42 ======================
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 24 úno 2016 19:42

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-02-2016
Ran by Adam (administrator) on DESKTOP-PC (24-02-2016 19:40:01)
Running from C:\Users\Adam\Desktop
Loaded Profiles: Adam (Available Profiles: Adam & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Language: Angličtina (Spojené státy)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Users\Adam\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(MSI) C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Cm108Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm108.dll,CMICtrlWnd
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2787264 2016-01-12] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [5595848 2015-07-08] (ESET)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [134616 2013-05-17] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [Super-Charger] => C:\Program Files (x86)\MSI\Super-Charger\Super-Charger.exe [506864 2013-03-08] (MSI)
HKLM-x32\...\Run: [OrderReminder] => C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe [98304 2006-01-30] (Hewlett-Packard)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\Run: [CtrlV.cz] => C:\Users\Adam\AppData\Local\Apps\2.0\4V6ND34G.AQW\7LPMD5ED.ON8\test..tion_0000000000000000_0001.0000_00504d2b24066b85\TestCtrlV.exe [39936 2014-12-19] ()
HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\Run: [uTorrent] => C:\Users\Adam\AppData\Roaming\uTorrent\utorrent.exe [398760 2014-04-14] (BitTorrent, Inc.)
HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8590760 2015-12-08] (Piriform Ltd)
SSODL: EldosMountNotificator-cbfs5 - {A60F8E2F-583F-4641-AF68-776D8752B85F} - C:\WINDOWS\system32\cbfsMntNtf5.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs5 - {A60F8E2F-583F-4641-AF68-776D8752B85F} - C:\WINDOWS\SysWOW64\cbfsMntNtf5.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: [EldosIconOverlay-cbfs5] -> {8BDBF8CA-5540-4871-90DA-631D42A319CE} => C:\WINDOWS\system32\cbfsMntNtf5.dll [2015-05-22] (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: [EldosIconOverlay-cbfs5] -> {8BDBF8CA-5540-4871-90DA-631D42A319CE} => C:\WINDOWS\SysWOW64\cbfsMntNtf5.dll [2015-05-22] (EldoS Corporation)
Startup: C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk [2015-12-10]
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{2d73bac2-2453-4f32-8952-edc3ddea458f}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3171289305-1862197294-184807748-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-10] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-10] (Oracle Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Adam\AppData\Roaming\Mozilla\Firefox\Profiles\q2tciqdz.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-10] ()
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-10] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-17] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-10] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-10] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3171289305-1862197294-184807748-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Adam\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [No File]
FF Plugin HKU\S-1-5-21-3171289305-1862197294-184807748-1000: SkypePlugin -> C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\npGatewayNpapi.dll [2016-01-15] (Skype Technologies S.A.)
FF Plugin HKU\S-1-5-21-3171289305-1862197294-184807748-1000: SkypePlugin64 -> C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\npGatewayNpapi-x64.dll [2016-01-15] (Skype Technologies S.A.)

Chrome:
=======
CHR HomePage: Profile 4 -> hxxp://www.google.cz/
CHR StartupUrls: Profile 4 -> "hxxps://www.facebook.com/","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=17.3.1.204&pid=safeguard&sg=&sap=hp","hxxps://www.facebook.com/
hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.0.5.292&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.5.512&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.7.598&pid=safeguard&sg=&sap=hp","hxxp://www.google.com","hxxps://mysearch.avg.com?cid={C4A61FDA-A582-4F9C-B885-7CEEB1869DF7}&mid=b918b38a61de47d280720574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&pr=fr&d=2014-08-31 09:56:20&v=3.2.0.14&pid=wtu&sg=&sap=hp","hxxps://mysearch.avg.com?cid={85BC40EF-E19C-44D2-A8F3-FA076BF52D1B}&mid=ed104666658547d2a3eb0574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-03 17:29:16&v=18.1.9.799&pid=safeguard&sg=&sap=hp"
CHR Profile: C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4
CHR Extension: (Prezentace Google) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-24]
CHR Extension: (Ovoce nakrájíme) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\afkpkaagbcebgebfcangeibbcjangpgd [2016-02-24]
CHR Extension: (Dokumenty Google) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-24]
CHR Extension: (Disk Google) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-24]
CHR Extension: (Volání přes Skype) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-02-24]
CHR Extension: (YouTube) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-24]
CHR Extension: (Adblock Plus) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-02-24]
CHR Extension: (Vyhledávání Google) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-24]
CHR Extension: (Punkový konzument) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ebmgejpgpphipjooiopnndkdiciedkdj [2016-02-24]
CHR Extension: (Tabulky Google) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-24]
CHR Extension: (Dokumenty Google offline) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-24]
CHR Extension: (AdBlock) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-02-24]
CHR Extension: (The West) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ilkgeioneoemibpddeiamfgiofnpjifm [2016-02-24]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-24]
CHR Extension: (Gmail) - C:\Users\Adam\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1353720 2015-07-08] (ESET)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S3 intelsba; C:\Program Files\Intel\Intel(R) Small Business Advantage\Service\Intel.SmallBusinessAdvantage.WindowsService.exe [48832 2013-03-13] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation)
R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [161264 2013-02-20] (MSI)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD.)
S4 MSSQL$ASUSHOMECLOUD; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.ASUSHOMECLOUD\MSSQL\Binn\sqlservr.exe [43130032 2015-03-30] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2015-11-14] ()
S4 SQLAgent$ASUSHOMECLOUD; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10_50.ASUSHOMECLOUD\MSSQL\Binn\SQLAGENT.EXE [381104 2015-03-30] (Microsoft Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6940944 2016-02-16] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 cbfs5; C:\WINDOWS\system32\drivers\cbfs5.sys [422080 2015-05-22] (EldoS Corporation)
R3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-04] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-09-22] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [251632 2015-07-14] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [169280 2014-09-22] (ESET)
R2 epfwwfpr; C:\Windows\system32\DRIVERS\epfwwfpr.sys [158968 2014-09-22] (ESET)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-02-17] ()
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] ()
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.)
R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super-Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R2 RealWoW60; C:\Windows\system32\DRIVERS\RealWoW60.sys [29400 2014-01-02] (Realtek semiconductor corp)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-24 19:40 - 2016-02-24 19:40 - 00020715 _____ C:\Users\Adam\Desktop\FRST.txt
2016-02-24 19:39 - 2016-02-24 19:40 - 00000000 ____D C:\FRST
2016-02-24 19:38 - 2016-02-24 19:39 - 02371072 _____ (Farbar) C:\Users\Adam\Desktop\FRST64.exe
2016-02-24 19:36 - 2016-02-24 19:36 - 00000000 ____D C:\Users\Adam\AppData\Local\ActiveSync
2016-02-24 19:35 - 2016-02-24 19:35 - 00000000 ___HD C:\OneDriveTemp
2016-02-24 19:34 - 2016-02-24 19:22 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-02-24 19:22 - 2016-02-24 19:32 - 00000000 ____D C:\zoek_backup
2016-02-24 19:22 - 2016-02-24 19:22 - 01309184 _____ C:\Users\Adam\Desktop\zoek.exe
2016-02-23 21:15 - 2016-02-23 21:15 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2016-02-23 21:09 - 2016-02-23 21:09 - 00003226 _____ C:\WINDOWS\System32\Tasks\{D44A9933-2294-4388-8859-4299DB44937C}
2016-02-23 16:35 - 2016-02-23 16:35 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-02-22 16:17 - 2016-02-22 16:19 - 00205824 _____ C:\Users\Adam\Desktop\výkaz prací 2016.xls
2016-02-22 15:57 - 2016-02-22 15:57 - 00000703 _____ C:\Users\Adam\Desktop\Fotky.lnk
2016-02-20 14:13 - 2016-02-21 16:22 - 00000000 ____D C:\WINDOWS\Minidump
2016-02-19 15:49 - 2016-02-24 19:13 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2016-02-19 15:49 - 2016-02-19 15:59 - 00000000 ____D C:\ProgramData\RogueKiller
2016-02-19 15:49 - 2016-02-19 15:49 - 25156680 _____ C:\Users\Adam\Desktop\RogueKillerX64.exe
2016-02-19 15:46 - 2016-02-19 15:46 - 00000791 _____ C:\Users\Adam\Desktop\JRT.txt
2016-02-19 15:45 - 2016-02-19 15:45 - 01609216 _____ (Malwarebytes) C:\Users\Adam\Desktop\JRT.exe
2016-02-18 23:33 - 2016-02-18 23:33 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-02-18 23:33 - 2016-02-18 23:33 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-02-18 23:33 - 2016-02-18 23:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-02-18 23:33 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-02-18 23:33 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-02-18 23:33 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-02-18 23:30 - 2016-02-19 15:42 - 00000000 ____D C:\AdwCleaner
2016-02-18 23:29 - 2016-02-18 23:30 - 01511424 _____ C:\Users\Adam\Desktop\AdwCleaner.exe
2016-02-18 23:20 - 2016-02-18 23:20 - 00448512 _____ (OldTimer Tools) C:\Users\Adam\Desktop\TFC.exe
2016-02-17 21:57 - 2016-02-17 21:57 - 00000000 _____ C:\autoexec.bat
2016-02-17 21:55 - 2016-02-17 21:55 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2016-02-17 21:33 - 2016-02-18 23:39 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-02-17 20:31 - 2016-02-18 00:48 - 00000000 ____D C:\Users\Adam\Desktop\hotovo
2016-02-16 14:44 - 2016-02-09 06:04 - 00111672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2016-02-16 14:43 - 2016-02-09 09:25 - 42983480 _____ C:\WINDOWS\system32\nvcompiler.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 37616184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 31119296 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 24944064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 21201784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 20741880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 17631304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 17224664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 17175248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 02541504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 02187712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00950328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00882232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00745408 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00689600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00423360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00383424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00379448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00378968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00348216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00317144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00153392 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-02-16 14:43 - 2016-02-09 09:25 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-02-12 20:25 - 2016-02-15 10:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-02-10 14:55 - 2016-01-27 06:56 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-02-10 14:55 - 2016-01-27 06:55 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-02-10 14:55 - 2016-01-27 06:37 - 01998176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-02-10 14:55 - 2016-01-27 06:10 - 22394368 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-02-10 14:55 - 2016-01-27 06:05 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-02-10 14:55 - 2016-01-27 06:05 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-02-10 14:55 - 2016-01-27 06:04 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-02-10 14:55 - 2016-01-27 05:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-02-10 14:55 - 2016-01-27 05:55 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-02-10 14:55 - 2016-01-27 05:54 - 24603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-02-10 14:55 - 2016-01-27 05:48 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-02-10 14:55 - 2016-01-27 05:41 - 03592704 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-02-10 14:54 - 2016-01-29 07:57 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-10 14:54 - 2016-01-29 07:33 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-10 14:54 - 2016-01-27 07:15 - 01557776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-02-10 14:54 - 2016-01-27 07:15 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-02-10 14:54 - 2016-01-27 07:01 - 07476064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-02-10 14:54 - 2016-01-27 07:01 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-02-10 14:54 - 2016-01-27 07:01 - 01819720 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-02-10 14:54 - 2016-01-27 06:59 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-10 14:54 - 2016-01-27 06:57 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-02-10 14:54 - 2016-01-27 06:57 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-10 14:54 - 2016-01-27 06:57 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-10 14:54 - 2016-01-27 06:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-10 14:54 - 2016-01-27 06:54 - 00295264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-02-10 14:54 - 2016-01-27 06:46 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-10 14:54 - 2016-01-27 06:46 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-10 14:54 - 2016-01-27 06:45 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-02-10 14:54 - 2016-01-27 06:45 - 06605544 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-02-10 14:54 - 2016-01-27 06:44 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-10 14:54 - 2016-01-27 06:44 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-10 14:54 - 2016-01-27 06:43 - 00359776 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-02-10 14:54 - 2016-01-27 06:37 - 00576352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-02-10 14:54 - 2016-01-27 06:21 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-10 14:54 - 2016-01-27 06:15 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-10 14:54 - 2016-01-27 06:13 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-02-10 14:54 - 2016-01-27 06:12 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-02-10 14:54 - 2016-01-27 06:11 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-10 14:54 - 2016-01-27 06:10 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-10 14:54 - 2016-01-27 06:08 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-10 14:54 - 2016-01-27 06:08 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-10 14:54 - 2016-01-27 06:07 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-10 14:54 - 2016-01-27 06:05 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-02-10 14:54 - 2016-01-27 06:05 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 24 úno 2016 19:42

2016-02-10 14:54 - 2016-01-27 06:04 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-10 14:54 - 2016-01-27 06:03 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-02-10 14:54 - 2016-01-27 06:02 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-10 14:54 - 2016-01-27 06:01 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-10 14:54 - 2016-01-27 05:59 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-10 14:54 - 2016-01-27 05:57 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-02-10 14:54 - 2016-01-27 05:55 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-02-10 14:54 - 2016-01-27 05:52 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-10 14:54 - 2016-01-27 05:50 - 02230784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-02-10 14:54 - 2016-01-27 05:50 - 01504768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-02-10 14:54 - 2016-01-27 05:50 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-10 14:54 - 2016-01-27 05:49 - 05662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-02-10 14:54 - 2016-01-27 05:44 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-10 14:54 - 2016-01-27 05:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-10 14:54 - 2016-01-27 05:39 - 02275328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-02-10 14:54 - 2016-01-27 05:38 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-02-10 14:54 - 2016-01-27 05:38 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-02-10 14:54 - 2016-01-27 05:37 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-02-10 14:54 - 2016-01-27 05:36 - 02757120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-02-10 14:54 - 2016-01-27 05:32 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-10 14:54 - 2016-01-27 05:31 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll
2016-02-07 16:13 - 2016-02-07 16:13 - 00027710 _____ C:\Users\Adam\Documents\cc_20160207_161349.reg
2016-02-06 15:26 - 2016-02-06 15:26 - 00003530 _____ C:\Users\Adam\Documents\cc_20160206_152611.reg
2016-02-06 14:45 - 2016-02-06 14:45 - 00029222 _____ C:\Users\Adam\Documents\cc_20160206_144514.reg
2016-02-06 14:17 - 2016-02-06 14:17 - 00000000 ____D C:\Users\Adam\AppData\Roaming\HomeCloudIDTool
2016-02-06 12:19 - 2016-02-06 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
2016-02-06 12:19 - 2008-08-18 19:18 - 00077824 _____ (Fox Magic Software) C:\WINDOWS\SysWOW64\fmcodec.DLL
2016-02-05 16:00 - 2016-02-05 16:00 - 00003370 _____ C:\Users\Adam\Documents\cc_20160205_160044.reg
2016-02-02 00:29 - 2016-02-02 00:29 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Sony Creative Software Inc
2016-01-31 15:33 - 2016-02-17 20:55 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Audacity
2016-01-31 15:33 - 2016-01-31 15:33 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-01-31 15:33 - 2016-01-31 15:33 - 00001076 _____ C:\Users\Adam\Desktop\Audacity.lnk
2016-01-31 15:33 - 2016-01-31 15:33 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-01-31 02:08 - 2016-02-02 23:57 - 00000000 ____D C:\Users\Adam\Documents\OFX Presets
2016-01-31 02:03 - 2016-01-31 02:03 - 00000000 ____D C:\Users\Adam\.cache
2016-01-31 00:25 - 2016-01-31 00:25 - 00000132 _____ C:\Users\Adam\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2016-01-31 00:23 - 2016-02-02 22:03 - 00000132 _____ C:\Users\Adam\AppData\Roaming\Adobe Formát GIF CS6 – předvolby
2016-01-30 23:23 - 2016-02-06 12:16 - 00000000 ____D C:\Users\Adam\AppData\Roaming\AnvSoft
2016-01-30 23:23 - 2016-01-30 23:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft
2016-01-30 23:23 - 2016-01-30 23:23 - 00000000 ____D C:\Program Files (x86)\AnvSoft
2016-01-30 23:17 - 2016-02-01 06:38 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Apple Computer
2016-01-30 23:12 - 2016-01-30 23:12 - 00000000 ____D C:\Users\Adam\AppData\LocalLow\Apple Computer
2016-01-30 23:07 - 2016-01-30 23:07 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Publish Providers
2016-01-30 23:06 - 2016-01-30 23:07 - 00000000 ____D C:\Users\Adam\AppData\Local\Sony
2016-01-30 23:06 - 2016-01-30 23:06 - 00000000 ____D C:\ProgramData\Sony
2016-01-30 23:06 - 2016-01-30 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2016-01-30 23:06 - 2016-01-30 23:06 - 00000000 ____D C:\Program Files\Sony
2016-01-30 23:06 - 2016-01-30 23:06 - 00000000 ____D C:\Program Files (x86)\Sony
2016-01-30 22:52 - 2016-01-31 01:41 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Sony
2016-01-30 18:20 - 2016-02-09 09:25 - 17116936 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-01-30 18:20 - 2016-01-23 04:31 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436175.dll
2016-01-30 18:20 - 2016-01-23 04:31 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436175.dll
2016-01-30 18:10 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2016-01-30 18:10 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2016-01-28 18:04 - 2016-01-16 07:37 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-01-28 18:04 - 2016-01-16 07:36 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-01-28 18:04 - 2016-01-16 07:36 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-01-28 18:04 - 2016-01-16 07:34 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-01-28 18:04 - 2016-01-16 07:24 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 08728920 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-01-28 18:04 - 2016-01-16 07:23 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-01-28 18:04 - 2016-01-16 07:21 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-01-28 18:04 - 2016-01-16 07:20 - 06971752 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-01-28 18:04 - 2016-01-16 07:20 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-01-28 18:04 - 2016-01-16 07:20 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-01-28 18:04 - 2016-01-16 07:20 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-01-28 18:04 - 2016-01-16 07:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-01-28 18:04 - 2016-01-16 07:19 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-01-28 18:04 - 2016-01-16 07:12 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-01-28 18:04 - 2016-01-16 07:09 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-01-28 18:04 - 2016-01-16 07:08 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-01-28 18:04 - 2016-01-16 07:08 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-01-28 18:04 - 2016-01-16 06:46 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-01-28 18:04 - 2016-01-16 06:45 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-28 18:04 - 2016-01-16 06:44 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-01-28 18:04 - 2016-01-16 06:44 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-01-28 18:04 - 2016-01-16 06:44 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-01-28 18:04 - 2016-01-16 06:43 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-01-28 18:04 - 2016-01-16 06:42 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-01-28 18:04 - 2016-01-16 06:42 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-01-28 18:04 - 2016-01-16 06:41 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-01-28 18:04 - 2016-01-16 06:40 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-01-28 18:04 - 2016-01-16 06:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-01-28 18:04 - 2016-01-16 06:40 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-01-28 18:04 - 2016-01-16 06:39 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-01-28 18:04 - 2016-01-16 06:38 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-01-28 18:04 - 2016-01-16 06:38 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-01-28 18:04 - 2016-01-16 06:38 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-01-28 18:04 - 2016-01-16 06:38 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-01-28 18:04 - 2016-01-16 06:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-01-28 18:04 - 2016-01-16 06:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-01-28 18:04 - 2016-01-16 06:37 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-01-28 18:04 - 2016-01-16 06:37 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-01-28 18:04 - 2016-01-16 06:36 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-01-28 18:04 - 2016-01-16 06:36 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-01-28 18:04 - 2016-01-16 06:36 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-01-28 18:04 - 2016-01-16 06:36 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-01-28 18:04 - 2016-01-16 06:36 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-01-28 18:04 - 2016-01-16 06:35 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-01-28 18:04 - 2016-01-16 06:35 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-01-28 18:04 - 2016-01-16 06:35 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-01-28 18:04 - 2016-01-16 06:34 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-01-28 18:04 - 2016-01-16 06:34 - 00590848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-01-28 18:04 - 2016-01-16 06:34 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-01-28 18:04 - 2016-01-16 06:34 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-01-28 18:04 - 2016-01-16 06:34 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-01-28 18:04 - 2016-01-16 06:33 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-01-28 18:04 - 2016-01-16 06:33 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-01-28 18:04 - 2016-01-16 06:33 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-01-28 18:04 - 2016-01-16 06:32 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-01-28 18:04 - 2016-01-16 06:32 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-01-28 18:04 - 2016-01-16 06:31 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-01-28 18:04 - 2016-01-16 06:31 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-01-28 18:04 - 2016-01-16 06:31 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-01-28 18:04 - 2016-01-16 06:31 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-01-28 18:04 - 2016-01-16 06:31 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-01-28 18:04 - 2016-01-16 06:30 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-01-28 18:04 - 2016-01-16 06:30 - 01053696 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-01-28 18:04 - 2016-01-16 06:30 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-01-28 18:04 - 2016-01-16 06:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-01-28 18:04 - 2016-01-16 06:30 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-01-28 18:04 - 2016-01-16 06:29 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-01-28 18:04 - 2016-01-16 06:29 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-01-28 18:04 - 2016-01-16 06:28 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-01-28 18:04 - 2016-01-16 06:28 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-01-28 18:04 - 2016-01-16 06:28 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-01-28 18:04 - 2016-01-16 06:28 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-01-28 18:04 - 2016-01-16 06:27 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-01-28 18:04 - 2016-01-16 06:26 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-01-28 18:04 - 2016-01-16 06:26 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-01-28 18:04 - 2016-01-16 06:26 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-01-28 18:04 - 2016-01-16 06:26 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-01-28 18:04 - 2016-01-16 06:25 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-01-28 18:04 - 2016-01-16 06:25 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-01-28 18:04 - 2016-01-16 06:25 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-01-28 18:04 - 2016-01-16 06:24 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-01-28 18:04 - 2016-01-16 06:24 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-01-28 18:04 - 2016-01-16 06:24 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-01-28 18:04 - 2016-01-16 06:24 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-01-28 18:04 - 2016-01-16 06:23 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-01-28 18:04 - 2016-01-16 06:23 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-01-28 18:04 - 2016-01-16 06:21 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-01-28 18:04 - 2016-01-16 06:20 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-01-28 18:04 - 2016-01-16 06:20 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-01-28 18:04 - 2016-01-16 06:20 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-01-28 18:04 - 2016-01-16 06:20 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-01-28 18:04 - 2016-01-16 06:19 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-01-28 18:04 - 2016-01-16 06:19 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-01-28 18:04 - 2016-01-16 06:19 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-01-28 18:04 - 2016-01-16 06:19 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-01-28 18:04 - 2016-01-16 06:18 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-01-28 18:04 - 2016-01-16 06:17 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-01-28 18:04 - 2016-01-16 06:16 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-01-28 18:04 - 2016-01-16 06:16 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-01-28 18:04 - 2016-01-16 06:15 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-01-28 18:04 - 2016-01-16 06:14 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-01-28 18:04 - 2016-01-16 06:14 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-01-28 18:04 - 2016-01-16 06:11 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-02-24 19:37 - 2014-11-01 22:41 - 00000000 ____D C:\Users\Adam\AppData\Roaming\uTorrent
2016-02-24 19:35 - 2015-07-15 20:04 - 00000978 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f.job
2016-02-24 19:35 - 2015-05-15 14:05 - 00000948 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec.job
2016-02-24 19:35 - 2015-04-10 14:26 - 00000000 ___RD C:\Users\Adam\OneDrive
2016-02-24 19:35 - 2015-02-05 01:59 - 00000948 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09.job
2016-02-24 19:35 - 2014-10-03 15:56 - 00000948 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-02-24 19:34 - 2015-12-08 05:43 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-24 19:34 - 2015-12-08 05:37 - 00000000 ____D C:\Users\Adam
2016-02-24 19:34 - 2015-12-08 05:36 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-24 19:34 - 2015-10-30 07:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-02-24 19:22 - 2014-10-04 12:10 - 00000000 ___RD C:\Users\Adam\Desktop\Zástupci
2016-02-24 19:14 - 2015-07-15 20:04 - 00000982 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800.job
2016-02-24 19:13 - 2014-10-26 10:36 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-02-24 19:10 - 2015-02-05 01:59 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e.job
2016-02-24 19:09 - 2015-05-15 14:05 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c.job
2016-02-24 19:04 - 2014-10-03 15:56 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-02-24 18:56 - 2014-10-10 17:03 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Skype
2016-02-24 18:16 - 2016-01-17 01:40 - 00000000 ____D C:\Users\Adam\AppData\Local\CrashDumps
2016-02-24 17:11 - 2015-09-04 13:41 - 00004198 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{4628C09A-E54D-4EA6-AFB3-089CAC69030C}
2016-02-24 16:49 - 2014-10-10 17:03 - 00000000 ____D C:\ProgramData\Skype
2016-02-24 15:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-02-24 09:37 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-02-24 07:38 - 2015-01-10 20:27 - 00000000 ____D C:\Users\Adam\AppData\Roaming\vlc
2016-02-23 18:39 - 2015-12-08 14:30 - 00875736 _____ C:\WINDOWS\system32\perfh005.dat
2016-02-23 18:39 - 2015-12-08 14:30 - 00200704 _____ C:\WINDOWS\system32\perfc005.dat
2016-02-23 18:39 - 2015-12-08 05:36 - 02173652 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-23 16:56 - 2015-12-08 05:37 - 00000000 ____D C:\Users\DefaultAppPool
2016-02-23 12:09 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-02-21 20:23 - 2015-08-02 19:23 - 00028306 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2016-02-20 14:24 - 2016-01-08 05:34 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2016-02-20 14:24 - 2014-10-17 19:09 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2016-02-20 13:04 - 2015-09-03 21:13 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-02-19 06:35 - 2014-11-17 12:12 - 00000000 ____D C:\Users\Adam\AppData\Local\ElevatedDiagnostics
2016-02-18 00:41 - 2015-11-15 14:42 - 00000279 _____ C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koš.lnk
2016-02-17 21:41 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SchCache
2016-02-17 21:38 - 2014-12-08 17:32 - 00000000 ____D C:\Program Files\Adobe
2016-02-16 23:57 - 2015-11-07 14:13 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-02-16 14:45 - 2015-12-08 05:36 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-16 14:45 - 2015-08-29 00:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-15 10:12 - 2014-10-03 18:00 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-02-12 14:44 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-02-12 14:18 - 2015-12-08 05:36 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2016-02-11 16:07 - 2015-08-02 01:09 - 00002424 _____ C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-10 20:34 - 2015-08-02 01:07 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-02-10 20:33 - 2015-10-30 10:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-02-10 17:01 - 2014-10-05 21:35 - 00000000 ____D C:\ProgramData\Oracle
2016-02-10 16:54 - 2015-11-14 16:22 - 00000000 ____D C:\Users\Adam\.oracle_jre_usage
2016-02-10 16:54 - 2014-10-21 17:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-10 16:54 - 2014-10-21 17:14 - 00000000 ____D C:\Program Files (x86)\Java
2016-02-10 16:53 - 2014-10-21 17:14 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2016-02-10 15:56 - 2014-10-03 16:32 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-02-10 15:53 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-02-10 15:53 - 2014-10-03 16:32 - 146614896 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-02-10 07:27 - 2015-11-21 16:28 - 12478528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-02-09 09:25 - 2015-11-21 16:28 - 19779648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-02-09 09:25 - 2015-11-21 16:28 - 14115136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-02-09 09:25 - 2015-11-21 16:28 - 03649576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-02-09 09:25 - 2015-11-21 16:28 - 03231544 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-02-09 09:25 - 2015-11-21 16:28 - 00035832 _____ C:\WINDOWS\system32\nvinfo.pb
2016-02-09 06:29 - 2015-12-23 21:10 - 00530368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-02-09 06:29 - 2015-12-23 21:10 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-09 06:29 - 2015-12-08 05:36 - 06368824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-02-09 06:29 - 2015-12-08 05:36 - 02992064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-02-09 06:29 - 2015-12-08 05:36 - 02561472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-02-09 06:29 - 2015-12-08 05:36 - 01263040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-02-09 06:29 - 2015-12-08 05:36 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-02-09 06:29 - 2015-12-08 05:36 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-02-09 06:24 - 2014-11-16 16:35 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2016-02-07 23:38 - 2014-11-09 11:16 - 00000000 ____D C:\ProgramData\Electronic Arts
2016-02-07 16:46 - 2016-01-03 19:19 - 00000000 ____D C:\Users\Adam\Desktop\Nová složka
2016-02-06 15:58 - 2015-12-08 05:36 - 06154909 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-06 15:15 - 2015-09-20 19:58 - 00000000 ____D C:\Users\Adam\AppData\Roaming\dvdcss
2016-02-06 14:38 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-06 14:37 - 2014-10-27 17:25 - 00000000 ____D C:\Users\Adam\AppData\Roaming\Ubisoft
2016-02-06 14:37 - 2014-10-27 17:23 - 00000000 ____D C:\ProgramData\Ubisoft
2016-02-06 14:37 - 2014-10-03 15:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-02-06 14:18 - 2015-10-18 22:09 - 00000000 __SHD C:\aws
2016-02-06 12:19 - 2015-04-16 14:36 - 00000000 ____D C:\Program Files (x86)\DsNET Corp
2016-02-06 02:47 - 2014-11-13 18:55 - 00000000 ____D C:\Users\Adam\Documents\Assassin's Creed Unity
2016-02-05 16:00 - 2015-08-02 01:07 - 00000000 ____D C:\Users\Adam\AppData\Local\Packages
2016-02-03 20:01 - 2015-10-30 08:26 - 00828920 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-02-03 20:01 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-02-02 23:09 - 2015-07-15 20:04 - 00004070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800
2016-02-02 23:09 - 2015-07-15 20:04 - 00003838 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f
2016-01-31 01:22 - 2014-11-21 19:32 - 00000000 ____D C:\Users\Adam\Documents\Freemake
2016-01-30 23:27 - 2015-04-10 19:23 - 00000000 ____D C:\Users\Adam\Documents\Any Video Converter
2016-01-30 18:21 - 2015-12-08 05:36 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-01-30 18:10 - 2015-08-29 00:03 - 00000000 ____D C:\Users\Adam\AppData\Local\NVIDIA
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-01-29 22:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr

==================== Files in the root of some directories =======

2015-08-02 01:16 - 2015-08-02 01:16 - 0000000 _____ () C:\Program Files (x86)\GX Gaming Junceus Headset
2016-01-31 00:23 - 2016-02-02 22:03 - 0000132 _____ () C:\Users\Adam\AppData\Roaming\Adobe Formát GIF CS6 – předvolby
2016-01-31 00:25 - 2016-01-31 00:25 - 0000132 _____ () C:\Users\Adam\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2015-11-14 18:37 - 2015-11-14 18:37 - 0007628 _____ () C:\Users\Adam\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-02-23 06:40

==================== End of FRST.txt ============================
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 24 úno 2016 19:42

Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-02-2016
Ran by Adam (2016-02-24 19:40:24)
Running from C:\Users\Adam\Desktop
Windows 10 Pro Version 1511 (X64) (2015-12-08 04:44:52)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Adam (S-1-5-21-3171289305-1862197294-184807748-1000 - Administrator - Enabled) => C:\Users\Adam
Administrator (S-1-5-21-3171289305-1862197294-184807748-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3171289305-1862197294-184807748-503 - Limited - Disabled)
Guest (S-1-5-21-3171289305-1862197294-184807748-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3171289305-1862197294-184807748-1007 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET NOD32 Antivirus 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET NOD32 Antivirus 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.010.20059 - Adobe Systems Incorporated)
Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.306 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Aktualizace NVIDIA 2.9.1.22 (Version: 2.9.1.22 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISE_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISE_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISE_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Any Video Converter 5.9.0 (HKLM-x32\...\Any Video Converter_is1) (Version: - Any-Video-Converter.com)
aTube Catcher verze 3.8 (HKLM-x32\...\{D43B360E-722D-421B-BC77-20B9E0F8B6CD}_is1) (Version: 3.8 - DsNET Corp)
Audacity 2.1.0 (HKLM-x32\...\Audacity_is1) (Version: 2.1.0 - Audacity Team)
Bandicam (HKLM-x32\...\Bandicam) (Version: 2.1.3.757 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandisoft.com)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.13 - Piriform)
CPUID HWMonitor 1.28 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
ESET NOD32 Antivirus (HKLM\...\{1D4A236B-9CC3-4387-86F8-DB5EE3A5D33A}) (Version: 8.0.319.1 - ESET, spol s r. o.)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
GDR 4042 for SQL Server 2008 R2 (KB3045313) (HKLM-x32\...\KB3045313) (Version: 10.52.4042.0 - Microsoft Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
GX Gaming Junceus Headset (HKLM-x32\...\{71B53BA8-4BE3-49AF-BC3E-07F392006300}) (Version: 1.00.0005 - KYE,Inc.)
HP OrderReminder (HKLM-x32\...\HP OrderReminder) (Version: 2.1 - )
Intel Android Device USB driver (HKLM\...\Intel Android Device USB driver) (Version: 1.10.0 - Intel)
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1011 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.10.1372 - Intel Corporation)
Intel(R) Small Business Advantage (HKLM-x32\...\{6A6D86CD-B004-46b7-8951-7BB75A776F8C}) (Version: 2.0.31.7101 - Intel(R) Corporation)
Intel(R) Update Manager (x32 Version: 1.0.0.36888 - Intel Corporation) Hidden
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LaserJet 1018 (HKLM-x32\...\HP-LaserJet 1018) (Version: - )
Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.)
Magical Jelly Bean KeyFinder (HKLM-x32\...\KeyFinder_is1) (Version: 2.0.10.10 - Magical Jelly Bean)
Malwarebytes Anti-Malware verze 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
MediaHuman YouTube to MP3 Converter verze 3.8.3 (HKLM-x32\...\MediaHuman YouTube to MP3 Converter_is1) (Version: 3.8.3 - )
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0405-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 (HKLM-x32\...\Microsoft SQL Server 2008 R2) (Version: - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Native Client (HKLM\...\{49860BCD-24D6-44C1-922E-AC12FE32234E}) (Version: 10.52.4042.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Setup (English) (HKLM-x32\...\{EFECC55D-7B0A-4D05-8487-CC2FD7C618A3}) (Version: 10.52.4042.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files (HKLM-x32\...\{D441BD04-E548-4F8E-97A4-1B66135BAAA8}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server Browser (HKLM-x32\...\{BF9BF038-FE03-429D-9B26-2FA0FD756052}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}) (Version: 10.52.4000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{3bcf8c72-b231-4d28-9f39-3405c22d8b5a}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 44.0.2 (x86 cs) (HKLM-x32\...\Mozilla Firefox 44.0.2 (x86 cs)) (Version: 44.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 44.0.2.5884 - Mozilla)
MSI GamingApp (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 1.0.0.3 - MSI)
NHL™ 09 (HKLM-x32\...\{827B97A9-B347-4110-9F89-37AF2B758F94}) (Version: 2.0.1.0 - Electronic Arts)
NVIDIA GeForce Experience 2.9.1.22 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.9.1.22 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.91 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 361.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.91 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Ovládací panel NVIDIA 361.91 (Version: 361.91 - NVIDIA Corporation) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.67.1226.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.0.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.2 - VS Revo Group, Ltd.)
Service Pack 2 for SQL Server 2008 R2 (KB2630458) (HKLM-x32\...\KB2630458) (Version: 10.52.4000.0 - Microsoft Corporation)
SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.9.1.22 - NVIDIA Corporation) Hidden
Shockwave (HKLM-x32\...\Shockwave) (Version: - )
Skype Web Plugin (HKLM-x32\...\{34E6C3B4-9354-41C2-9484-25B17F48E7E9}) (Version: 7.13.0.71 - Skype Technologies S.A.)
Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
SQL Server 2008 R2 SP2 Common Files (x32 Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Services (x32 Version: 10.52.4000.0 - Microsoft Corporation) Hidden
SQL Server 2008 R2 SP2 Database Engine Shared (x32 Version: 10.52.4000.0 - Microsoft Corporation) Hidden
Sql Server Customer Experience Improvement Program (x32 Version: 10.50.1600.1 - Microsoft Corporation) Hidden
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Super-Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.018 - MSI)
System Requirements Lab Detection (HKLM-x32\...\{88690CD4-CF31-48F0-9AF0-2049A27096FA}) (Version: 2.2.3.0 - Husdawg, LLC)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.55321 - TeamViewer)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Vegas Pro 13.0 (64-bit) (HKLM\...\{77CEFB5E-CCC3-11E4-8043-F04DA23A5C58}) (Version: 13.0.444 - Sony)
VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.5 - MSI)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM-x32\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3171289305-1862197294-184807748-1000_Classes\CLSID\{34BEB704-B055-4D67-9AC1-C852E0E3DFA4}\localserver32 -> C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\GatewayVersion-x64.exe (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-3171289305-1862197294-184807748-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Adam\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3171289305-1862197294-184807748-1000_Classes\CLSID\{79DF62FC-32CA-4F29-A0C2-FBD17AB15D63}\InprocServer32 -> C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\GatewayActiveX-x64.dll (Skype Technologies S.A.)
CustomCLSID: HKU\S-1-5-21-3171289305-1862197294-184807748-1000_Classes\CLSID\{CBF9CD8C-2714-4F36-B76A-43E6C7547BC2}\localserver32 -> C:\Users\Adam\AppData\Local\SkypePlugin\7.13.0.71\EdgeCalling.exe (Skype Technologies S.A.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {017A0B84-A19B-40E7-A273-39E0F8014C36} - System32\Tasks\{61E52461-F804-4D85-B6AA-C0BE9CA27EDF} => D:\mafia\Mafia II\pc\mafia2.exe
Task: {04037BFE-4557-4BA4-AE02-DC89D7E36FBC} - System32\Tasks\AsusCloud-checkhealthclient => C:\Program Files\ASUS\HomeCloud\ASUSCloud\SchedulerJob\AP\checkhealthclient\OmniStore\RestartSevice.bat
Task: {0BA36982-9F8B-47FC-961C-9D6253B02694} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {130D8732-E9E6-4C9A-B450-0BDEAA19C9DC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {21B45B4F-C687-47D8-BC3A-972C063B3A35} - System32\Tasks\{740D9DB0-992F-42C4-9ECE-4251B3240C95} => D:\NHL 09\nhl2009.exe [2008-10-23] ()
Task: {24714040-C886-4006-AE21-E2CACCFB7FA1} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {26599302-00ED-4C8F-8335-811404D1CECB} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {2675A143-97C3-49C3-BB4F-957BA70D603A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {2B0BEF13-39AA-4046-8F63-16A8E77A83AC} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {2D5747B3-784F-4047-B9A3-A8D970DB076F} - System32\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {35BDD7B9-11F0-44DF-AC8A-45A941DC23E8} - System32\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {37BEA9C3-185F-486A-A788-26727FC75508} - System32\Tasks\{83C14074-3374-49AE-898E-0F5345536947} => D:\GTA SA\GTA San Andreas\gta_sa.exe
Task: {3869277D-FB22-4316-AC32-2F6B9F3BC0CB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3CC6A038-180A-4ABD-8FD7-7FD9B92EE9AB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
Task: {3F635CAF-4810-4F4E-9745-C963C2016D71} - System32\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4636758D-775D-4F3A-994F-79A8CB972C93} - System32\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {53226A41-662F-4ECC-BBFC-3C2C887DE808} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {55EACC47-2199-461B-B896-0F104D7B7B71} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {57E95C82-3C48-442B-A6B1-C82168EE8613} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {581267BD-031F-493E-98C1-D6DF589D665E} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {5AB7FCCE-51CC-4178-BBC3-6A57FEBDC331} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {5FF403AE-8BE8-4915-83A6-C9ACAFFDDF02} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {67FC5BD4-7717-4697-9EF0-735794971621} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {699A7483-3EA7-4FA2-8F10-FC00A05C1878} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {70B8D09E-F343-49FF-B09D-B6DE3DF14A73} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {7AF40A3C-F145-431E-BE4C-47F3621FBFCB} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {8027E4A1-237F-4C4E-AEDD-0DD6E759F111} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {8562E760-8F6B-486C-BEDB-EA901130D00B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {8979299F-B67D-4D97-B1B1-E2919E081984} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {8DBC2BEC-23A1-4FF2-A438-7D58E952695A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8E22604C-E054-43BD-9A89-8517CBBC329F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {95EE763A-08E7-41DD-AFC5-3AD9F8546CDE} - System32\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9803FE45-9E55-4644-BB0C-B5C4E8F8CF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9A9E442F-6577-4614-B1F9-423AD123FA8D} - System32\Tasks\{06CAE3AD-71B1-4ACE-89A8-938027B44D8D} => pcalua.exe -a "D:\LIS\Life Is Strange\Binaries\Win32\LifeIsStrange.exe" -d "D:\LIS\Life Is Strange\Binaries\Win32"
Task: {9AD62C96-B7D4-424C-9E4E-23037522FA7A} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {9D1D21DF-D20A-44EE-A8F2-EB6ECAF6D9CF} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {9F2CE1C7-AE25-426A-AC5C-678FE86332C6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A1118C61-12F4-48A7-BCF7-815AA2321B62} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {A2043801-F2BB-4DB5-B0E2-03CC3648B2F5} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {A2207CC2-14AE-4B42-8CB3-D9C5DA97D1C9} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {A26A1C14-1523-415C-8EAD-0AF98188C98D} - System32\Tasks\{44EBD599-8FED-4175-947F-871747402FC4} => pcalua.exe -a "E:\Stažené soubory Chrome\deauthNHL2009.exe" -d "E:\Stažené soubory Chrome"
Task: {A4412AC9-6059-41E0-8F0F-738A1A4C6231} - System32\Tasks\{D44A9933-2294-4388-8859-4299DB44937C} => Chrome.exe hxxp://ui.skype.com/ui/0/7.18.85.112/cs ... Error=1618
Task: {AF167EE8-875F-426F-9535-55F332F94CC7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-12-08] (Piriform Ltd)
Task: {B7392D35-D9B7-4C0F-BBCA-2109BD72ACEF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {BAACB203-3F7A-4715-9F9D-76F42AA490B3} - System32\Tasks\{F6954ED6-0F9C-4C4A-8CA7-E758F2602F3E} => D:\mafia\Mafia II\pc\mafia2.exe
Task: {C060DA4D-0E0A-4CAD-8DFE-8754B6E309D7} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D068835C-2FC0-46DB-93E7-29B72CDCD1AB} - System32\Tasks\Intel(R) Small Business Advantage\Notifier => C:\Program Files\Intel\Intel(R) Small Business Advantage\UI\SBA_Notifier.exe [2013-03-13] (Intel Corporation)
Task: {D99312F7-92D1-4745-86AA-AC7CF876E16F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {DC260D3C-E9F7-4491-8D62-0E25ADF44166} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {E20290D9-D375-488D-BB28-4FC21B6108A6} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {E421A42B-9C66-4CB5-A804-00CBD87B2E29} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {E4AAD4E4-8B47-48D1-A054-234C8535BBAC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-02-10] (Adobe Systems Incorporated)
Task: {FA6507B9-8718-43B9-8B13-9C49B8D960A7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-02-10] (Microsoft Corporation)
Task: {FA8B92BB-A40E-4C11-925B-AF921EF459ED} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-12-08 05:36 - 2016-02-09 06:29 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-10-03 18:28 - 2012-09-18 14:27 - 00192512 _____ () C:\WINDOWS\System32\zlhp1020.dll
2015-12-08 05:36 - 2012-09-18 14:27 - 00065024 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\pphp1020.dll
2014-10-27 17:12 - 2015-11-14 17:48 - 00076888 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe
2015-12-23 21:04 - 2016-01-12 05:43 - 00291264 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2015-12-08 14:32 - 2015-12-08 14:32 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-08 14:32 - 2015-12-08 14:32 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-01-22 14:53 - 2016-01-22 14:53 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-17 21:00 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2015-12-17 21:00 - 2015-12-07 05:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 16:33 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 16:33 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 18:04 - 2016-01-16 06:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 18:04 - 2016-01-16 06:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2014-09-18 08:23 - 2014-09-18 08:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll
2014-10-14 19:51 - 2014-10-14 19:51 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll
2014-09-18 08:23 - 2014-09-18 08:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll
2014-10-14 19:51 - 2014-10-14 19:51 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll
2016-01-22 14:53 - 2016-01-22 14:53 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-22 14:53 - 2016-01-22 14:54 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-08-29 00:03 - 2016-01-12 05:43 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2014-10-03 15:57 - 2013-05-17 00:05 - 01199576 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2016-02-24 19:23 - 00000753 ____A C:\WINDOWS\system32\Drivers\etc\hosts


127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3171289305-1862197294-184807748-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Adam\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{1b7e42fd-1a1f-4b6f-8d4e-63f99fb243be}.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\StartupApproved\StartupFolder: => "Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk"
HKU\S-1-5-21-3171289305-1862197294-184807748-1000\...\StartupApproved\Run: => "CtrlV.cz"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{F8997057-73F2-40A7-A3A7-11DAC0134048}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{52F4D82E-8FBC-4799-A4ED-C92FAFDAA724}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{62955980-5216-4943-8FCA-7EC7B97B60BB}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{D9AAC9AD-01A7-4D63-9908-E76B1ABB8EC8}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{BC13D51E-442E-4AB9-9FDE-DFAC981EC147}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{1D1BA290-EC59-4AE8-9F22-A842619D237C}] => (Allow) D:\Steam\bin\steamwebhelper.exe
FirewallRules: [{5BA808BD-0FBD-446D-9C83-0B0F714819D8}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{DFB42084-EA71-407E-B2A3-B817B731CDD6}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3D709B00-C7A2-490F-B629-FC91269ACC63}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{A81357E9-69E0-48DC-BFFA-8A9F20A1AEFB}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A365D030-EA86-465F-A494-8B59CE27A236}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{36EFD1A7-0095-44CE-93D7-CCFE33D69E5D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{CA70297D-A8E6-458E-8F02-C4B55723055E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{23809587-7051-472A-9F8C-AE640F90D446}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B43810E6-0417-4242-9846-44570B69CC60}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{A224F763-4285-43A3-945F-B99E666296C9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{299610B1-D0AA-4C1A-859A-538641278506}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{363EDDC0-7392-4730-BFE2-7F998E72617B}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1FE83AFB-A127-4906-8D9D-564086A99D28}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{0659A205-E802-491E-B715-621781FC7046}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{F56DD42D-76C6-4B0E-8FAB-7B4BF0CB51D6}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{E7EFD741-9C95-4D35-813C-8615752E1856}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{7DDA3018-DEC1-4155-9150-F9E31D6DE8CA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{50B63B64-4E89-4B4D-A8F8-568A988CBB46}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{2495B47A-C5DC-40F2-BE7B-7E09D889A142}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{D384B6C9-EA24-4A55-B28C-EA7B736785F5}C:\users\adam\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\adam\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [UDP Query User{5AFABB47-4023-4FB9-98A3-AC9D845265E6}C:\users\adam\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\adam\appdata\roaming\utorrent\utorrent.exe
FirewallRules: [{FA05AAE1-DFB4-408D-B66A-53C63F0B2AF7}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{781B3F40-0B43-413C-AD8E-AF845AC730FA}] => (Allow) C:\Program Files\Logitech Gaming Software\LCore.exe
FirewallRules: [{D1154C3A-EE24-4DEA-9B87-EF64B16E5703}] => (Allow) LPort=443
FirewallRules: [{3E7EF82C-8BF1-42C4-8416-0417E03BF891}] => (Allow) LPort=3658
FirewallRules: [{1197AFBF-8D6B-4F71-8EFB-34F898DE14CD}] => (Allow) LPort=13200
FirewallRules: [{768116CD-C6E7-4A8D-815E-5F13CD7B291A}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{ACDF88A8-5C83-4519-87C6-6C83FBDF0063}] => (Allow) C:\Users\Adam\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{C6BAABB7-08BB-4829-8004-81D6A4231D69}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{EC261FB5-6BFC-4531-AF4A-1C67D933E889}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{72E8BA90-2488-441D-8DE6-61E162056DBE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B92CA662-E36A-4EEC-B4AC-FCBA22A26450}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{F8E3A760-0F3E-487E-9B9A-D15A4CFB1A96}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{2B1CF96E-77D9-4F7D-B1EC-FEB9BB816BC9}] => (Allow) D:\Steam\SteamApps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{26BCE8A0-252C-4FE2-A618-A34C97182833}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{40DFA3D3-75B7-4BCE-BE1E-7EF9262052BA}] => (Allow) LPort=2869
FirewallRules: [{CA503D24-E48E-47AA-B8BB-2779440ECADA}] => (Allow) LPort=1900
FirewallRules: [{F5700E10-82F5-4F52-9F4C-29D0D74D6533}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{863077A0-BA5D-4692-AB36-EF0E75CB600C}] => (Allow) C:\Users\Adam\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{64E0496F-978C-481E-A27D-35FC018222CE}] => (Allow) D:\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{8548D7AD-EC70-4B8B-A702-D13D6F06B2A5}] => (Allow) D:\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{DE04E108-AB6D-461C-BBF6-14761B9E69FA}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{FCF87734-5C0D-4F78-A5CA-26B270026090}] => (Allow) D:\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{D6FAAF07-EE86-42CF-BC4A-1A28F776D919}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{4D3A2303-67B4-49DC-9136-F5F51ABC82D5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{7C706574-4E2F-409B-A930-DF2BA2A77D78}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{0EF60A4D-30D7-4BDD-8CE9-8C3E4F0D7D45}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{EA31408F-CD37-4981-8B92-AF8D40D65E72}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe

==================== Restore Points =========================

24-02-2016 19:23:11 zoek.exe restore point

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/24/2016 07:23:12 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (02/24/2016 06:16:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: portal2.exe, verze: 0.0.0.0, časové razítko: 0x5432e000
Název chybujícího modulu: nvd3dum.dll, verze: 10.18.13.6191, časové razítko: 0x56b96ecd
Kód výjimky: 0xc0000005
Posun chyby: 0x007741a6
ID chybujícího procesu: 0x1374
Čas spuštění chybující aplikace: 0xportal2.exe0
Cesta k chybující aplikaci: portal2.exe1
Cesta k chybujícímu modulu: portal2.exe2
ID zprávy: portal2.exe3
Úplný název chybujícího balíčku: portal2.exe4
ID aplikace související s chybujícím balíčkem: portal2.exe5

Error: (02/24/2016 04:27:55 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: SQLAgent$ASUSHOMECLOUD8

Error: (02/24/2016 04:27:54 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: MSSQL$ASUSHOMECLOUD8

Error: (02/24/2016 04:27:54 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (02/24/2016 07:46:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2016

Error: (02/24/2016 07:46:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2016

Error: (02/24/2016 07:46:46 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (02/23/2016 11:10:56 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: vlc.exe, verze: 2.2.1.0, časové razítko: 0x00000000
Název chybujícího modulu: libqt4_plugin.dll, verze: 2.2.1.0, časové razítko: 0xa2d0a2c0
Kód výjimky: 0x40000015
Posun chyby: 0x000000000076310b
ID chybujícího procesu: 0x1cc0
Čas spuštění chybující aplikace: 0xvlc.exe0
Cesta k chybující aplikaci: vlc.exe1
Cesta k chybujícímu modulu: vlc.exe2
ID zprávy: vlc.exe3
Úplný název chybujícího balíčku: vlc.exe4
ID aplikace související s chybujícím balíčkem: vlc.exe5

Error: (02/23/2016 05:41:50 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-PC)
Description: Aplikaci Microsoft.Messaging_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 se nepovedlo aktivovat, protože došlo k chybě: -2147023174. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.


System errors:
=============
Error: (02/24/2016 07:34:55 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: Služba NetTcpActivator závisí na službě NetTcpPortSharing, která neuspěla při spuštění v důsledku následující chyby:
%%1058

Error: (02/24/2016 07:34:21 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {7006698D-2974-4091-A424-85DD0B909E23}

Error: (02/24/2016 07:34:21 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-PC)
Description: {7006698D-2974-4091-A424-85DD0B909E23}

Error: (02/24/2016 07:34:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba User Data Access_f5d331 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (02/24/2016 07:34:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba User Data Storage_f5d331 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (02/24/2016 07:34:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Contact Data_f5d331 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (02/24/2016 07:34:21 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Sync Host_f5d331 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restart the service.

Error: (02/24/2016 07:32:36 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (02/24/2016 07:32:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (02/24/2016 07:32:35 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


CodeIntegrity:
===================================
Date: 2016-02-11 21:42:32.622
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-02-10 20:34:47.620
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-02-10 16:54:54.954
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-01-31 02:51:28.169
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-01-30 02:23:29.141
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-01-14 12:03:05.761
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-01-07 13:51:14.687
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2016-01-06 18:47:41.435
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-12-30 13:01:59.194
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

Date: 2015-12-18 10:23:30.448
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4430 CPU @ 3.00GHz
Percentage of memory in use: 19%
Total physical RAM: 8117.25 MB
Available physical RAM: 6548.14 MB
Total Virtual: 16309.25 MB
Available Virtual: 14733.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:111.79 GB) (Free:57.95 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (Hry) (Fixed) (Total:310.5 GB) (Free:262.96 GB) NTFS
Drive e: (Knihovna) (Fixed) (Total:310.5 GB) (Free:271.75 GB) NTFS
Drive f: (Torrenty) (Fixed) (Total:310.51 GB) (Free:97.53 GB) NTFS
Drive g: (Dexter 3 serie) (CDROM) (Total:4.12 GB) (Free:0 GB) CDFS
Drive h: (Filmy) (Fixed) (Total:372.61 GB) (Free:63.37 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 372.6 GB) (Disk ID: FD22FD22)
Partition 1: (Not Active) - (Size=372.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 76C473B3)
Partition 1: (Active) - (Size=111.8 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 76C473DE)
Partition 1: (Not Active) - (Size=310.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=310.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=310.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod jaro3 » 25 úno 2016 09:38

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CloseProcesses:
CHR StartupUrls: Profile 4 -> "hxxps://www.facebook.com/","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=17.3.1.204&pid=safeguard&sg=&sap=hp","hxxps://www.facebook.com/
hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.0.5.292&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.5.512&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.7.598&pid=safeguard&sg=&sap=hp","hxxp://www.google.com","hxxps://mysearch.avg.com?cid={C4A61FDA-A582-4F9C-B885-7CEEB1869DF7}&mid=b918b38a61de47d280720574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&pr=fr&d=2014-08-31 09:56:20&v=3.2.0.14&pid=wtu&sg=&sap=hp","hxxps://mysearch.avg.com?cid={85BC40EF-E19C-44D2-A8F3-FA076BF52D1B}&mid=ed104666658547d2a3eb0574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-03 17:29:16&v=18.1.9.799&pid=safeguard&sg=&sap=hp"
U3 idsvc; no ImagePath
C:\WINDOWS\System32\Tasks\{D44A9933-2294-4388-8859-4299DB44937C}
2016-02-02 23:09 - 2015-07-15 20:04 - 00004070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800
2016-02-02 23:09 - 2015-07-15 20:04 - 00003838 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f
Task: {3869277D-FB22-4316-AC32-2F6B9F3BC0CB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3F635CAF-4810-4F4E-9745-C963C2016D71} - System32\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4636758D-775D-4F3A-994F-79A8CB972C93} - System32\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {57E95C82-3C48-442B-A6B1-C82168EE8613} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {5AB7FCCE-51CC-4178-BBC3-6A57FEBDC331} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {699A7483-3EA7-4FA2-8F10-FC00A05C1878} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {70B8D09E-F343-49FF-B09D-B6DE3DF14A73} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {7AF40A3C-F145-431E-BE4C-47F3621FBFCB} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {8DBC2BEC-23A1-4FF2-A438-7D58E952695A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8E22604C-E054-43BD-9A89-8517CBBC329F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {95EE763A-08E7-41DD-AFC5-3AD9F8546CDE} - System32\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9803FE45-9E55-4644-BB0C-B5C4E8F8CF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9F2CE1C7-AE25-426A-AC5C-678FE86332C6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {B7392D35-D9B7-4C0F-BBCA-2109BD72ACEF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {C060DA4D-0E0A-4CAD-8DFE-8754B6E309D7} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 25 úno 2016 21:42

Fix result of Farbar Recovery Scan Tool (x64) Version:24-02-2016
Ran by Adam (2016-02-25 21:39:25) Run:1
Running from C:\Users\Adam\Desktop
Loaded Profiles: Adam (Available Profiles: Adam & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CHR StartupUrls: Profile 4 -> "hxxps://www.facebook.com/","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=17.3.1.204&pid=safeguard&sg=&sap=hp","hxxps://www.facebook.com/
hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.0.5.292&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.5.512&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.7.598&pid=safeguard&sg=&sap=hp","hxxp://www.google.com","hxxps://mysearch.avg.com?cid={C4A61FDA-A582-4F9C-B885-7CEEB1869DF7}&mid=b918b38a61de47d280720574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&pr=fr&d=2014-08-31 09:56:20&v=3.2.0.14&pid=wtu&sg=&sap=hp","hxxps://mysearch.avg.com?cid={85BC40EF-E19C-44D2-A8F3-FA076BF52D1B}&mid=ed104666658547d2a3eb0574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-03 17:29:16&v=18.1.9.799&pid=safeguard&sg=&sap=hp"
U3 idsvc; no ImagePath
C:\WINDOWS\System32\Tasks\{D44A9933-2294-4388-8859-4299DB44937C}
2016-02-02 23:09 - 2015-07-15 20:04 - 00004070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800
2016-02-02 23:09 - 2015-07-15 20:04 - 00003838 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f
Task: {3869277D-FB22-4316-AC32-2F6B9F3BC0CB} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {3F635CAF-4810-4F4E-9745-C963C2016D71} - System32\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4636758D-775D-4F3A-994F-79A8CB972C93} - System32\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {57E95C82-3C48-442B-A6B1-C82168EE8613} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {5AB7FCCE-51CC-4178-BBC3-6A57FEBDC331} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {699A7483-3EA7-4FA2-8F10-FC00A05C1878} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {70B8D09E-F343-49FF-B09D-B6DE3DF14A73} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {7AF40A3C-F145-431E-BE4C-47F3621FBFCB} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {8DBC2BEC-23A1-4FF2-A438-7D58E952695A} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8E22604C-E054-43BD-9A89-8517CBBC329F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {95EE763A-08E7-41DD-AFC5-3AD9F8546CDE} - System32\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9803FE45-9E55-4644-BB0C-B5C4E8F8CF50} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9F2CE1C7-AE25-426A-AC5C-678FE86332C6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {B7392D35-D9B7-4C0F-BBCA-2109BD72ACEF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {C060DA4D-0E0A-4CAD-8DFE-8754B6E309D7} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

EmptyTemp:
End

*****************

Processes closed successfully.
Chrome StartupUrls => removed successfully
hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.0.5.292&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.0.443&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.5.512&pid=safeguard&sg=&sap=hp","hxxp://mysearch.avg.com?cid={A3DF71A3-A244-46ED-8F85-AAC294D24537}&mid=f34e1d06434147d389080574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-02-05 21:41:48&v=18.1.7.598&pid=safeguard&sg=&sap=hp","hxxp://www.google.com","hxxps://mysearch.avg.com?cid={C4A61FDA-A582-4F9C-B885-7CEEB1869DF7}&mid=b918b38a61de47d280720574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&pr=fr&d=2014-08-31 09:56:20&v=3.2.0.14&pid=wtu&sg=&sap=hp","hxxps://mysearch.avg.com?cid={85BC40EF-E19C-44D2-A8F3-FA076BF52D1B}&mid=ed104666658547d2a3eb0574380631a5-dcec47ecf59652a6eedf9e58fb74297452f3149c&lang=cs&ds=AVG&coid=avgtbavg&cmpid=&pr=fr&d=2014-09-03 17:29:16&v=18.1.9.799&pid=safeguard&sg=&sap=hp" => Error: No automatic fix found for this entry.
idsvc => service removed successfully
C:\WINDOWS\System32\Tasks\{D44A9933-2294-4388-8859-4299DB44937C} => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800 => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3869277D-FB22-4316-AC32-2F6B9F3BC0CB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3869277D-FB22-4316-AC32-2F6B9F3BC0CB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3F635CAF-4810-4F4E-9745-C963C2016D71}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F635CAF-4810-4F4E-9745-C963C2016D71}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore1d08f0fddc811ec" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4636758D-775D-4F3A-994F-79A8CB972C93}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4636758D-775D-4F3A-994F-79A8CB972C93}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d08f0fdde5d38c" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{57E95C82-3C48-442B-A6B1-C82168EE8613}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57E95C82-3C48-442B-A6B1-C82168EE8613}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5AB7FCCE-51CC-4178-BBC3-6A57FEBDC331}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AB7FCCE-51CC-4178-BBC3-6A57FEBDC331}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{699A7483-3EA7-4FA2-8F10-FC00A05C1878}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{699A7483-3EA7-4FA2-8F10-FC00A05C1878}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{70B8D09E-F343-49FF-B09D-B6DE3DF14A73}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70B8D09E-F343-49FF-B09D-B6DE3DF14A73}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7AF40A3C-F145-431E-BE4C-47F3621FBFCB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AF40A3C-F145-431E-BE4C-47F3621FBFCB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8DBC2BEC-23A1-4FF2-A438-7D58E952695A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DBC2BEC-23A1-4FF2-A438-7D58E952695A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8E22604C-E054-43BD-9A89-8517CBBC329F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8E22604C-E054-43BD-9A89-8517CBBC329F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{95EE763A-08E7-41DD-AFC5-3AD9F8546CDE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{95EE763A-08E7-41DD-AFC5-3AD9F8546CDE}" => key removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA1d040def55d416e" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9803FE45-9E55-4644-BB0C-B5C4E8F8CF50}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9803FE45-9E55-4644-BB0C-B5C4E8F8CF50}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9F2CE1C7-AE25-426A-AC5C-678FE86332C6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9F2CE1C7-AE25-426A-AC5C-678FE86332C6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B7392D35-D9B7-4C0F-BBCA-2109BD72ACEF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7392D35-D9B7-4C0F-BBCA-2109BD72ACEF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C060DA4D-0E0A-4CAD-8DFE-8754B6E309D7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C060DA4D-0E0A-4CAD-8DFE-8754B6E309D7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040def534ca09.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f0fddc811ec.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0bf3124fa2a1f.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d040def55d416e.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d08f0fdde5d38c.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA1d0bf3125188800.job => moved successfully
EmptyTemp: => 707.8 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 21:39:31 ====
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod jerabina » 25 úno 2016 21:44

Co problémy?
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 26 úno 2016 13:10

Odblešení je hotové? No jako momentálně nepozoruju žádný problém ;) Jestli je kontrola hotová tak děkuju :)
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate

Uživatelský avatar
jerabina
člen Security týmu
Level 6
Level 6
Příspěvky: 3647
Registrován: březen 13
Bydliště: Litoměřice
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod jerabina » 26 úno 2016 21:19

V tom případě:

Stáhni si zde DelFix
https://toolslib.net/downloads/viewdownload/2-delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore) .
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci.

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy, je to vše a můžeš dát vyřešeno - zelenou "fajfku" ;)
Když nevíš jak dál, přichází na řadu prostudovat manuál!
HJT návod

Pokud neodpovídám do vašich témat v sekci HJT když jsem online, tak je to jen proto, že jsem na mobilu kde je studování logů a psaní skriptů nemožné. Neberte to tedy prosím jako ignoraci.

Adam15
Level 3
Level 3
Příspěvky: 517
Registrován: červenec 11
Pohlaví: Muž
Stav:
Offline

Re: COM surogate

Příspěvekod Adam15 » 06 bře 2016 15:46

# DelFix v1.011 - Logfile created 06/03/2016 at 15:46:06
# Updated 18/08/2015 by Xplode
# Username : Adam - DESKTOP-PC
# Operating System : Windows 10 Pro (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #3 [Windows Update | 03/02/2016 11:41:25]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
OS - Windows 7 Ultimate 64 Bit
zdroj - OCZ 550W
CPU - intel core i5-4430
RAM - 8 Gb
GPU - Nvidia GeForce N760
MB - MSI B85-G41 PC Mate


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 9 hostů