Zamrzá počítač - FRST log
Napsal: 17 led 2014 19:41
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 17-01-2014 02
Ran by Stanley (administrator) on STANLEY-HP on 17-01-2014 19:37:10
Running from C:\Users\Stanley\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\stacsv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\AEstSrv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSMA32.EXE
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSHDLL32.EXE
() C:\ProgramData\DatacardService\HWDeviceService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\ProgramData\O2 Internet\OnlineUpdate\ouc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(F-Secure Corporation) C:\Program Files\F-Secure\FWES\program\fsdfwd.exe
(F-Secure Corporation) C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Apple Computer, Inc.) C:\Program Files\QuickTime\qttask.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSM32.EXE
() C:\Program Files\AVG Secure Search\vprot.exe
(PowerISO Computing, Inc.) C:\Program Files\PowerISO\PWRISOVM.EXE
() C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\O2 Internet\O2 Internet.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QLBController] - C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-04-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-17] (IDT, Inc.)
HKLM\...\Run: [estar] - C:\System.Sav\Util\HideDOS.EXE [77824 2006-11-28] ()
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [1277952 2009-11-13] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF6 Registry Controller] - C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [110880 2009-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [Nuance PDF Reader-reminder] - C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [NortonOnlineBackupReminder] - C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [282624 2006-09-01] (Apple Computer, Inc.)
HKLM\...\Run: [F-Secure Manager] - C:\Program Files\F-Secure\Common\FSM32.EXE [199264 2009-08-05] (F-Secure Corporation)
HKLM\...\Run: [F-Secure TNB] - C:\Program Files\F-Secure\FSGUI\TNBUtil.exe [2349664 2009-08-05] (F-Secure Corporation)
HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2486296 2014-01-10] ()
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [307200 2011-06-15] (PowerISO Computing, Inc.)
HKLM\...\Run: [SweetIM] - C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] - C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-11-23] (Sonic Solutions)
HKCU\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1515576 2010-02-10] ()
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
MountPoints2: {5b10f10c-4eb9-11e3-bca1-70f3957e76f7} - H:\AutoRun.exe
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
HKU\TEMP\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
URLSearchHook: HKLM - BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... F3957E76F7}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... F3957E76F7}
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
Toolbar: HKLM - Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM - BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
Winsock: Catalog9 01 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 02 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 03 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 04 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 05 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 06 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 07 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 08 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 09 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 10 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 11 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 23 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Tcpip\..\Interfaces\{90EA314E-F84F-4564-BDFA-30BC3B9D4A59}: [NameServer]160.218.161.60 194.228.211.33
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Dokumenty Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-10]
CHR Extension: (Disk Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-10]
CHR Extension: (YouTube) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-10]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-10]
CHR Extension: (AVG Security Toolbar) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-01-10]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-10]
CHR Extension: (Gmail) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-10]
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2014-01-10]
CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx [2014-01-10]
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx [2014-01-10]
========================== Services (Whitelisted) =================
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
R2 F-Secure Gatekeeper Handler Starter; C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe [215648 2009-08-05] (F-Secure Corporation)
R3 FSDFWD; C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe [522848 2010-12-25] (F-Secure Corporation)
R2 FSMA; C:\Program Files\F-Secure\Common\FSMA32.EXE [186976 2009-08-05] (F-Secure Corporation)
R3 FSORSPClient; C:\Program Files\F-Secure\ORSP Client\fsorsp.exe [60352 2013-06-06] (F-Secure Corporation)
R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
S2 O2 Internet. RunOuc; C:\Program Files\O2 Internet\UpdateDog\ouc.exe [657504 2012-11-12] ()
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc)
R2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [134944 2009-11-03] (Nuance Communications, Inc.)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2010-03-17] (IDT, Inc.)
R2 vToolbarUpdater17.3.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-10] (AVG Secure Search)
S2 HP Support Assistant Service; "C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [x]
==================== Drivers (Whitelisted) ====================
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2012-06-17] ()
R1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [37664 2013-11-26] (AVG Technologies)
R3 F-Secure Gatekeeper; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys [145856 2013-07-11] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files\F-Secure\HIPS\drivers\fshs.sys [68064 2009-08-05] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44240 2012-08-16] ()
R1 FSES; C:\Windows\System32\drivers\fses.sys [36792 2010-12-25] (F-Secure Corporation)
R1 FSFW; C:\Windows\System32\drivers\fsdfw.sys [73224 2013-05-07] (F-Secure Corporation)
R1 fsvista; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsvista.sys [12384 2009-08-05] ()
R3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [97408 2013-01-25] (Huawei Technologies Co., Ltd.)
R3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27776 2013-01-23] (Huawei Technologies Co., Ltd.)
R3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [207360 2013-02-17] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2012-06-17] ()
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [78848 2010-05-21] (Realtek Semiconductor Corp.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-17 19:37 - 2014-01-17 19:37 - 00019938 _____ C:\Users\Stanley\Desktop\FRST.txt
2014-01-17 19:36 - 2014-01-17 19:36 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Zeon
2014-01-17 19:35 - 2014-01-17 19:35 - 01220096 _____ (Farbar) C:\Users\Stanley\Desktop\FRST.exe
2014-01-17 19:35 - 2014-01-17 19:35 - 00000000 ____D C:\FRST
2014-01-17 19:34 - 2014-01-17 19:35 - 02075648 _____ (Farbar) C:\Users\Stanley\Downloads\FRST64.exe
2014-01-16 18:06 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2014-01-16 18:06 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-01-16 18:06 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-01-12 21:32 - 2014-01-12 21:32 - 00001220 _____ C:\Users\Stanley\Desktop\Spybot - Search & Destroy.lnk
2014-01-10 21:18 - 2014-01-10 21:18 - 00000000 ____D C:\Users\Stanley\AppData\Local\Google
2014-01-10 19:46 - 2014-01-10 19:46 - 00000000 ____D C:\Users\Stanley\AppData\Local\Hewlett-Packard
2014-01-10 19:44 - 2014-01-10 19:44 - 00125208 _____ C:\Users\Stanley\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\Documents\Bluetooth Exchange Folder
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\ATI
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\Broadcom
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\AVG Secure Search
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\ATI
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Hewlett-Packard
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Local\PDFC
2014-01-10 19:41 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley
2014-01-10 19:41 - 2014-01-10 19:41 - 00001397 _____ C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Šablony
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Soubory cookie
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Poslední
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní tiskárny
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní síť
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Nabídka Start
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Dokumenty
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Obrázky
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Hudba
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Filmy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Local\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Adobe
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Local\VirtualStore
2014-01-10 19:41 - 2010-10-15 21:04 - 00000000 ____D C:\Users\Stanley\AppData\Local\Microsoft Help
2014-01-10 19:41 - 2010-04-25 08:46 - 00000020 ___SH C:\Users\Stanley\ntuser.ini
2014-01-10 19:41 - 2009-07-14 05:42 - 00000000 ___RD C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-10 19:41 - 2009-07-14 05:37 - 00000000 ___RD C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-01-10 19:27 - 2014-01-10 19:36 - 00000000 ____D C:\všechno
2014-01-10 19:01 - 2014-01-10 19:01 - 00000000 _____ C:\windows\system32\fa.log
2014-01-08 22:04 - 2010-10-15 21:04 - 00000000 ____D C:\Users\TEMP\AppData\Local\Microsoft Help
2014-01-08 22:04 - 2010-04-25 08:46 - 00000020 ___SH C:\Users\TEMP\ntuser.ini
2014-01-08 22:04 - 2009-07-14 05:42 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-08 22:04 - 2009-07-14 05:37 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
2014-01-17 19:37 - 2014-01-17 19:37 - 00019938 _____ C:\Users\Stanley\Desktop\FRST.txt
2014-01-17 19:36 - 2014-01-17 19:36 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Zeon
2014-01-17 19:35 - 2014-01-17 19:35 - 01220096 _____ (Farbar) C:\Users\Stanley\Desktop\FRST.exe
2014-01-17 19:35 - 2014-01-17 19:35 - 00000000 ____D C:\FRST
2014-01-17 19:35 - 2014-01-17 19:34 - 02075648 _____ (Farbar) C:\Users\Stanley\Downloads\FRST64.exe
2014-01-17 19:23 - 2010-08-10 22:55 - 01440879 _____ C:\windows\WindowsUpdate.log
2014-01-17 19:23 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-17 19:23 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-17 19:22 - 2010-06-01 01:09 - 01606374 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-17 19:15 - 2010-10-10 11:51 - 00000938 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-17 19:15 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-17 19:15 - 2009-07-14 05:39 - 00147102 _____ C:\windows\setupact.log
2014-01-16 23:48 - 2010-10-10 11:51 - 00000942 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-16 19:53 - 2009-07-14 05:33 - 01800712 _____ C:\windows\system32\FNTCACHE.DAT
2014-01-16 19:37 - 2010-06-01 01:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-16 19:35 - 2013-08-19 17:00 - 00000000 ____D C:\windows\system32\MRT
2014-01-16 19:33 - 2010-10-10 11:29 - 83425928 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-01-14 19:29 - 2010-06-01 01:25 - 00000000 ____D C:\ProgramData\PDFC
2014-01-12 21:32 - 2014-01-12 21:32 - 00001220 _____ C:\Users\Stanley\Desktop\Spybot - Search & Destroy.lnk
2014-01-12 21:32 - 2010-12-25 16:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-12 21:32 - 2010-12-25 16:10 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2014-01-11 22:35 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET
2014-01-10 23:25 - 2010-06-01 01:58 - 00082190 _____ C:\windows\PFRO.log
2014-01-10 23:05 - 2012-07-13 13:25 - 00000000 ____D C:\Program Files\AVG Secure Search
2014-01-10 21:18 - 2014-01-10 21:18 - 00000000 ____D C:\Users\Stanley\AppData\Local\Google
2014-01-10 19:46 - 2014-01-10 19:46 - 00000000 ____D C:\Users\Stanley\AppData\Local\Hewlett-Packard
2014-01-10 19:44 - 2014-01-10 19:44 - 00125208 _____ C:\Users\Stanley\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\Documents\Bluetooth Exchange Folder
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\ATI
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\Broadcom
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\AVG Secure Search
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\ATI
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Hewlett-Packard
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Local\PDFC
2014-01-10 19:43 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley
2014-01-10 19:41 - 2014-01-10 19:41 - 00001397 _____ C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Šablony
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Soubory cookie
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Poslední
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní tiskárny
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní síť
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Nabídka Start
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Dokumenty
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Obrázky
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Hudba
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Filmy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Local\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Adobe
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Local\VirtualStore
2014-01-10 19:36 - 2014-01-10 19:27 - 00000000 ____D C:\všechno
2014-01-10 19:01 - 2014-01-10 19:01 - 00000000 _____ C:\windows\system32\fa.log
2014-01-09 21:49 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\LogFiles
2014-01-07 16:09 - 2013-09-13 18:55 - 00000328 _____ C:\windows\Tasks\HPCeeScheduleForStanley.job
2014-01-04 11:00 - 2009-07-14 05:53 - 00032596 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-12-30 13:58 - 2012-11-13 16:58 - 00002828 ___SH C:\ProgramData\KGyGaAvL.sys
2013-12-30 13:58 - 2012-11-13 16:58 - 00000088 __RSH C:\ProgramData\5A5F160E13.sys
2013-12-26 15:56 - 2012-07-13 13:25 - 00000000 ____D C:\ProgramData\AVG Secure Search
2013-12-26 15:56 - 2012-07-13 13:25 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2013-12-26 10:36 - 2010-11-04 15:56 - 00000284 _____ C:\windows\Tasks\AppleSoftwareUpdate.job
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-12 20:55
==================== End Of Log ============================
Ran by Stanley (administrator) on STANLEY-HP on 17-01-2014 19:37:10
Running from C:\Users\Stanley\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atiesrxx.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\stacsv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\AEstSrv.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agrsmsvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsgk32.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSMA32.EXE
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSHDLL32.EXE
() C:\ProgramData\DatacardService\HWDeviceService.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\ProgramData\O2 Internet\OnlineUpdate\ouc.exe
(PDF Complete Inc) C:\Program Files\PDF Complete\pdfsvc.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe
(Protexis Inc.) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(AVG Secure Search) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Safer Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
() C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\loggingserver.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
(F-Secure Corporation) C:\Program Files\F-Secure\FWES\program\fsdfwd.exe
(F-Secure Corporation) C:\Program Files\F-Secure\ORSP Client\fsorsp.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray.exe
(Nuance Communications, Inc.) C:\Program Files\Nuance\PDF Professional 6\PdfPro6Hook.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Apple Computer, Inc.) C:\Program Files\QuickTime\qttask.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Common\FSM32.EXE
() C:\Program Files\AVG Secure Search\vprot.exe
(PowerISO Computing, Inc.) C:\Program Files\PowerISO\PWRISOVM.EXE
() C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(F-Secure Corporation) C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
(Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe
(Hewlett-Packard Development Company L.P.) C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files\O2 Internet\O2 Internet.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [QLBController] - C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe [256056 2010-03-01] (Hewlett-Packard Company)
HKLM\...\Run: [PDF Complete] - C:\Program Files\PDF Complete\pdfsty.exe [563736 2010-03-06] (PDF Complete Inc)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-04-05] (Hewlett-Packard)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-04-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe [495708 2010-03-17] (IDT, Inc.)
HKLM\...\Run: [estar] - C:\System.Sav\Util\HideDOS.EXE [77824 2006-11-28] ()
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Professional 6\pdfpro6hook.exe [1277952 2009-11-13] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF6 Registry Controller] - C:\Program Files\Nuance\PDF Professional 6\RegistryController.exe [110880 2009-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [Nuance PDF Reader-reminder] - C:\Program Files\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM\...\Run: [NortonOnlineBackupReminder] - C:\Program Files\Symantec\Norton Online Backup\Activation\NOBuActivation.exe [3331944 2009-12-03] (Symantec Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [282624 2006-09-01] (Apple Computer, Inc.)
HKLM\...\Run: [F-Secure Manager] - C:\Program Files\F-Secure\Common\FSM32.EXE [199264 2009-08-05] (F-Secure Corporation)
HKLM\...\Run: [F-Secure TNB] - C:\Program Files\F-Secure\FSGUI\TNBUtil.exe [2349664 2009-08-05] (F-Secure Corporation)
HKLM\...\Run: [vProt] - C:\Program Files\AVG Secure Search\vprot.exe [2486296 2014-01-10] ()
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\PowerISO\PWRISOVM.EXE [307200 2011-06-15] (PowerISO Computing, Inc.)
HKLM\...\Run: [SweetIM] - C:\Program Files\SweetIM\Messenger\SweetIM.exe [115032 2012-10-04] (SweetIM Technologies Ltd.)
HKLM\...\Run: [Sweetpacks Communicator] - C:\Program Files\SweetIM\Communicator\SweetPacksUpdateManager.exe [231768 2012-08-15] (SweetIM Technologies Ltd.)
HKLM\...\runonceex: [ContentMerger] - c:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-11-23] (Sonic Solutions)
HKCU\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1515576 2010-02-10] ()
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2363392 2010-02-22] (Hewlett-Packard Company)
HKCU\...\Run: [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
MountPoints2: {5b10f10c-4eb9-11e3-bca1-70f3957e76f7} - H:\AutoRun.exe
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
HKU\TEMP\...\Run: [HPAdvisorDock] - C:\Program Files\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [ 2010-02-10] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
URLSearchHook: HKLM - BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... F3957E76F7}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {EEE6C360-6118-11DC-9C72-001320C79847} URL = http://search.sweetim.com/search.asp?sr ... F3957E76F7}
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: PlusIEEventHelper Class - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: ZeonIEEventHelper Class - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: SweetPacks Browser Helper - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
Toolbar: HKLM - Nuance PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
Toolbar: HKLM - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\17.3.0.49\AVG Secure Search_toolbar.dll (AVG Secure Search)
Toolbar: HKLM - BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\prxtbBS_P.dll (Conduit Ltd.)
Toolbar: HKLM - SweetPacks Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll (AVG Secure Search)
Winsock: Catalog9 01 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 02 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 03 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 04 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 05 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 06 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 07 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 08 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 09 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 10 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 11 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Winsock: Catalog9 23 C:\Program Files\F-Secure\FSPS\program\FSLSP.DLL [183904] (F-Secure Corporation)
Tcpip\..\Interfaces\{90EA314E-F84F-4564-BDFA-30BC3B9D4A59}: [NameServer]160.218.161.60 194.228.211.33
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Extension: (Dokumenty Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-10]
CHR Extension: (Disk Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-10]
CHR Extension: (YouTube) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-10]
CHR Extension: (Vyhled\u00E1v\u00E1n\u00ED Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-10]
CHR Extension: (AVG Security Toolbar) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof [2014-01-10]
CHR Extension: (Pen\u011B\u017Eenka Google) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-10]
CHR Extension: (Gmail) - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-10]
CHR HKLM\...\Chrome\Extension: [jcdgjdiieiljkfkdcloehkohchhpekkn] - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx [2014-01-10]
CHR HKLM\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx [2014-01-10]
CHR HKLM\...\Chrome\Extension: [ogccgbmabaphcakpiclgcnmcnimhokcj] - C:\Users\Stanley\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetNT.crx [2014-01-10]
========================== Services (Whitelisted) =================
R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agrsmsvc.exe [14336 2009-11-02] (LSI Corporation)
R2 F-Secure Gatekeeper Handler Starter; C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe [215648 2009-08-05] (F-Secure Corporation)
R3 FSDFWD; C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe [522848 2010-12-25] (F-Secure Corporation)
R2 FSMA; C:\Program Files\F-Secure\Common\FSMA32.EXE [186976 2009-08-05] (F-Secure Corporation)
R3 FSORSPClient; C:\Program Files\F-Secure\ORSP Client\fsorsp.exe [60352 2013-06-06] (F-Secure Corporation)
R2 HP Wireless Assistant Service; C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe [103992 2010-04-05] (Hewlett-Packard)
R2 hpHotkeyMonitor; C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe [264248 2010-03-01] (Hewlett-Packard Company)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
S2 O2 Internet. RunOuc; C:\Program Files\O2 Internet\UpdateDog\ouc.exe [657504 2012-11-12] ()
R2 pdfcDispatcher; C:\Program Files\PDF Complete\pdfsvc.exe [635416 2010-03-06] (PDF Complete Inc)
R2 PDFProFiltSrv; C:\Program Files\Nuance\PDF Professional 6\PDFProFiltSrv.exe [134944 2009-11-03] (Nuance Communications, Inc.)
R2 SBSDWSCService; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 STacSV; C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_7b6e808b01435efc\STacSV.exe [229458 2010-03-17] (IDT, Inc.)
R2 vToolbarUpdater17.3.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [1771544 2014-01-10] (AVG Secure Search)
S2 HP Support Assistant Service; "C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe" [x]
==================== Drivers (Whitelisted) ====================
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [271360 2012-06-17] ()
R1 avgtp; C:\windows\system32\drivers\avgtpx86.sys [37664 2013-11-26] (AVG Technologies)
R3 F-Secure Gatekeeper; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsgk.sys [145856 2013-07-11] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files\F-Secure\HIPS\drivers\fshs.sys [68064 2009-08-05] (F-Secure Corporation)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44240 2012-08-16] ()
R1 FSES; C:\Windows\System32\drivers\fses.sys [36792 2010-12-25] (F-Secure Corporation)
R1 FSFW; C:\Windows\System32\drivers\fsdfw.sys [73224 2013-05-07] (F-Secure Corporation)
R1 fsvista; C:\Program Files\F-Secure\Anti-Virus\minifilter\fsvista.sys [12384 2009-08-05] ()
R3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [97408 2013-01-25] (Huawei Technologies Co., Ltd.)
R3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [27776 2013-01-23] (Huawei Technologies Co., Ltd.)
R3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [207360 2013-02-17] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [18048 2012-06-17] ()
R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [78848 2010-05-21] (Realtek Semiconductor Corp.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-17 19:37 - 2014-01-17 19:37 - 00019938 _____ C:\Users\Stanley\Desktop\FRST.txt
2014-01-17 19:36 - 2014-01-17 19:36 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Zeon
2014-01-17 19:35 - 2014-01-17 19:35 - 01220096 _____ (Farbar) C:\Users\Stanley\Desktop\FRST.exe
2014-01-17 19:35 - 2014-01-17 19:35 - 00000000 ____D C:\FRST
2014-01-17 19:34 - 2014-01-17 19:35 - 02075648 _____ (Farbar) C:\Users\Stanley\Downloads\FRST64.exe
2014-01-16 18:06 - 2013-11-27 02:14 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbhub.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbport.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00076288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbccgp.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbehci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00024064 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbuhci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00020480 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbohci.sys
2014-01-16 18:06 - 2013-11-27 02:13 - 00006016 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usbd.sys
2014-01-16 18:06 - 2013-11-26 12:11 - 00240576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
2014-01-16 18:06 - 2013-11-26 11:10 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-01-12 21:32 - 2014-01-12 21:32 - 00001220 _____ C:\Users\Stanley\Desktop\Spybot - Search & Destroy.lnk
2014-01-10 21:18 - 2014-01-10 21:18 - 00000000 ____D C:\Users\Stanley\AppData\Local\Google
2014-01-10 19:46 - 2014-01-10 19:46 - 00000000 ____D C:\Users\Stanley\AppData\Local\Hewlett-Packard
2014-01-10 19:44 - 2014-01-10 19:44 - 00125208 _____ C:\Users\Stanley\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\Documents\Bluetooth Exchange Folder
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\ATI
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\Broadcom
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\AVG Secure Search
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\ATI
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Hewlett-Packard
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Local\PDFC
2014-01-10 19:41 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley
2014-01-10 19:41 - 2014-01-10 19:41 - 00001397 _____ C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Šablony
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Soubory cookie
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Poslední
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní tiskárny
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní síť
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Nabídka Start
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Dokumenty
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Obrázky
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Hudba
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Filmy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Local\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Adobe
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Local\VirtualStore
2014-01-10 19:41 - 2010-10-15 21:04 - 00000000 ____D C:\Users\Stanley\AppData\Local\Microsoft Help
2014-01-10 19:41 - 2010-04-25 08:46 - 00000020 ___SH C:\Users\Stanley\ntuser.ini
2014-01-10 19:41 - 2009-07-14 05:42 - 00000000 ___RD C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-10 19:41 - 2009-07-14 05:37 - 00000000 ___RD C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-01-10 19:27 - 2014-01-10 19:36 - 00000000 ____D C:\všechno
2014-01-10 19:01 - 2014-01-10 19:01 - 00000000 _____ C:\windows\system32\fa.log
2014-01-08 22:04 - 2010-10-15 21:04 - 00000000 ____D C:\Users\TEMP\AppData\Local\Microsoft Help
2014-01-08 22:04 - 2010-04-25 08:46 - 00000020 ___SH C:\Users\TEMP\ntuser.ini
2014-01-08 22:04 - 2009-07-14 05:42 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-01-08 22:04 - 2009-07-14 05:37 - 00000000 ___RD C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
==================== One Month Modified Files and Folders =======
2014-01-17 19:37 - 2014-01-17 19:37 - 00019938 _____ C:\Users\Stanley\Desktop\FRST.txt
2014-01-17 19:36 - 2014-01-17 19:36 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Zeon
2014-01-17 19:35 - 2014-01-17 19:35 - 01220096 _____ (Farbar) C:\Users\Stanley\Desktop\FRST.exe
2014-01-17 19:35 - 2014-01-17 19:35 - 00000000 ____D C:\FRST
2014-01-17 19:35 - 2014-01-17 19:34 - 02075648 _____ (Farbar) C:\Users\Stanley\Downloads\FRST64.exe
2014-01-17 19:23 - 2010-08-10 22:55 - 01440879 _____ C:\windows\WindowsUpdate.log
2014-01-17 19:23 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-17 19:23 - 2009-07-14 05:34 - 00019760 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-17 19:22 - 2010-06-01 01:09 - 01606374 _____ C:\windows\system32\PerfStringBackup.INI
2014-01-17 19:15 - 2010-10-10 11:51 - 00000938 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-17 19:15 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2014-01-17 19:15 - 2009-07-14 05:39 - 00147102 _____ C:\windows\setupact.log
2014-01-16 23:48 - 2010-10-10 11:51 - 00000942 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-16 19:53 - 2009-07-14 05:33 - 01800712 _____ C:\windows\system32\FNTCACHE.DAT
2014-01-16 19:37 - 2010-06-01 01:32 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-16 19:35 - 2013-08-19 17:00 - 00000000 ____D C:\windows\system32\MRT
2014-01-16 19:33 - 2010-10-10 11:29 - 83425928 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-01-14 19:29 - 2010-06-01 01:25 - 00000000 ____D C:\ProgramData\PDFC
2014-01-12 21:32 - 2014-01-12 21:32 - 00001220 _____ C:\Users\Stanley\Desktop\Spybot - Search & Destroy.lnk
2014-01-12 21:32 - 2010-12-25 16:10 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2014-01-12 21:32 - 2010-12-25 16:10 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy
2014-01-11 22:35 - 2009-07-14 03:37 - 00000000 ____D C:\windows\Microsoft.NET
2014-01-10 23:25 - 2010-06-01 01:58 - 00082190 _____ C:\windows\PFRO.log
2014-01-10 23:05 - 2012-07-13 13:25 - 00000000 ____D C:\Program Files\AVG Secure Search
2014-01-10 21:18 - 2014-01-10 21:18 - 00000000 ____D C:\Users\Stanley\AppData\Local\Google
2014-01-10 19:46 - 2014-01-10 19:46 - 00000000 ____D C:\Users\Stanley\AppData\Local\Hewlett-Packard
2014-01-10 19:44 - 2014-01-10 19:44 - 00125208 _____ C:\Users\Stanley\AppData\Local\GDIPFONTCACHEV1.DAT
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\Documents\Bluetooth Exchange Folder
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\ATI
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\Broadcom
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\AVG Secure Search
2014-01-10 19:44 - 2014-01-10 19:44 - 00000000 ____D C:\Users\Stanley\AppData\Local\ATI
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Hewlett-Packard
2014-01-10 19:43 - 2014-01-10 19:43 - 00000000 ____D C:\Users\Stanley\AppData\Local\PDFC
2014-01-10 19:43 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley
2014-01-10 19:41 - 2014-01-10 19:41 - 00001397 _____ C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Šablony
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Soubory cookie
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Poslední
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní tiskárny
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Okolní síť
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Nabídka Start
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Dokumenty
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Obrázky
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Hudba
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Documents\Filmy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 _SHDL C:\Users\Stanley\AppData\Local\Data aplikací
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Roaming\Adobe
2014-01-10 19:41 - 2014-01-10 19:41 - 00000000 ____D C:\Users\Stanley\AppData\Local\VirtualStore
2014-01-10 19:36 - 2014-01-10 19:27 - 00000000 ____D C:\všechno
2014-01-10 19:01 - 2014-01-10 19:01 - 00000000 _____ C:\windows\system32\fa.log
2014-01-09 21:49 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\LogFiles
2014-01-07 16:09 - 2013-09-13 18:55 - 00000328 _____ C:\windows\Tasks\HPCeeScheduleForStanley.job
2014-01-04 11:00 - 2009-07-14 05:53 - 00032596 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-12-30 13:58 - 2012-11-13 16:58 - 00002828 ___SH C:\ProgramData\KGyGaAvL.sys
2013-12-30 13:58 - 2012-11-13 16:58 - 00000088 __RSH C:\ProgramData\5A5F160E13.sys
2013-12-26 15:56 - 2012-07-13 13:25 - 00000000 ____D C:\ProgramData\AVG Secure Search
2013-12-26 15:56 - 2012-07-13 13:25 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
2013-12-26 10:36 - 2010-11-04 15:56 - 00000284 _____ C:\windows\Tasks\AppleSoftwareUpdate.job
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-12 20:55
==================== End Of Log ============================