Zdarvím, budiž log
pardon že mi to tak trvalo, trochu mě tlačil termín semestrálky
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by Drakuba (administrator) on DRAKUBA-PC on 18-10-2013 13:27:16
Running from C:\Users\Drakuba\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
() C:\Program Files\GIGABYTE\EnergySaver2\des2svr.exe
() C:\Windows\System32\XSrvSetup.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\Windows\system32\PnkBstrA.exe
(Gigabyte Technology CO., LTD.) C:\Program Files\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\ProgramData\Premium\OptimizerPro\OptimizerPro.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files\GIGABYTE\GHOST\Tilt.exe
(Saitek) C:\Program Files\Saitek\CyborgKeyboard\SaiVolume.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(BitTorrent, Inc.) C:\Program Files\AAA Čtecí prográmky\uTorrent\utorrent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTLite.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Gigabyte Technology CO., LTD.) C:\Program Files\GIGABYTE\Smart6\Timelock\AlarmClock.exe
(Nero AG) C:\Program Files\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.3.107.0\SeaPort.exe
(forum.viry.cz) C:\Users\Drakuba\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43632 2010-01-19] ()
HKLM\...\Run: [PWRISOVM.EXE] - C:\Program Files\AAA Čtecí prográmky\PowerISO\PWRISOVM.EXE [180224 2009-03-15] (PowerISO Computing, Inc.)
HKLM\...\Run: [CanonSolutionMenu] - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [689488 2008-03-11] (CANON INC.)
HKLM\...\Run: [CanonMyPrinter] - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [1848648 2009-07-07] (CANON INC.)
HKLM\...\Run: [Tilt] - C:\Program Files\GIGABYTE\GHOST\Tilt.exe [724992 2009-06-26] ()
HKLM\...\Run: [SaiVolume] - C:\Program Files\Saitek\CyborgKeyboard\SaiVolume.exe [126976 2008-01-18] (Saitek)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Kies\KiesTrayAgent.exe [3521424 2012-03-31] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [BambooCore] - C:\Program Files\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS6ServiceManager] - C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [681032 2013-10-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ProfilerU] - C:\Program Files\SmartTechnology\Software\ProfilerU.exe [327680 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] - C:\Program Files\SmartTechnology\Software\SaiMfd.exe [122880 2013-04-16] (Saitek)
HKCU\...\Run: [KiesHelper] - C:\Program Files\Kies\KiesHelper.exe [954256 2012-03-31] (Samsung)
HKCU\...\Run: [KiesPDLR] - C:\Program Files\Kies\External\FirmwareUpdate\KiesPDLR.exe [21392 2012-03-31] ()
HKCU\...\Run: [uTorrent] - C:\Program Files\AAA Čtecí prográmky\uTorrent\utorrent.exe [394616 2010-11-10] (BitTorrent, Inc.)
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-05] (DT Soft Ltd)
HKCU\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [221184 2005-02-17] (InstallShield Software Corporation)
IMEO\backitup.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\bamboo dock.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\bjmyprt.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\chrome.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\cnslmain.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\consumer_cpl.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\images2pdf.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\kies.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\lightscribecontrolpanel.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\lslauncher.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\mip.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\pccompanion.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\pdf architect.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\poweriso.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\prefutil.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\pwrisovm.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\realconverter.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\realplay.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\realtrimmer.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\rnxproc.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\shapecollector.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\tabtip.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\uninst.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
IMEO\uninstall.exe: [Debugger] "C:\Program Files\TuneUp Utilities 2012\TUAutoReactivator32.exe"
Startup: C:\Users\Drakuba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.3.lnk
ShortcutTarget: OpenOffice.org 2.3.lnk -> C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
ProxyServer: 10.176.171.237:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.delta-search.com/?babsrc=HP_ ... 6&tsp=4933
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://www.delta-search.com/?q={searchT ... 6&tsp=4933
SearchScopes: HKCU - {CF739809-1C6C-47C0-85B9-569DBB141420} URL =
http://toolbar.ask.com/toolbarv/askRedi ... toolbar=PD
SearchScopes: HKCU - {EEF4D0CB-5497-445d-A2F6-0D64518188A3} URL =
http://uk.search.yahoo.com/search?p={se ... &type=IEBD
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.3.107.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
Toolbar: HKCU -Ask Toolbar - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 10.109.133.254 10.109.255.254
FireFox:
========
FF ProfilePath: C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default
FF NewTab: hxxp://
www.delta-search.com/?babsrc=NT_ss&mntr ... 6&tsp=4933
FF Homepage: hxxp://
www.seznam.cz/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @esn.me/esnsonar,version=0.70.4 - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin: @esn/esnlaunch,version=1.104.0 - C:\Program Files\Battlelog Web Plugins\1.104.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin: @esn/esnlaunch,version=1.122.0 - C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin: @real.com/nppl3260;version=12.0.1.609 - C:\Program Files\AAA Přehrávače\Real player\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=12.0.1.609 - C:\Program Files\AAA Přehrávače\Real player\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprphtml5videoshim;version=12.0.1.609 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=12.0.1.609 - C:\Program Files\AAA Přehrávače\Real player\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\AAA Přehrávače\VLC\npvlc.dll (VideoLAN)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Drakuba\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Battlefield Heroes Updater - C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default\Extensions\
battlefieldheroespatcher@ea.com
FF Extension: České slovníky pro kontrolu pravopisu - C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default\Extensions\
cs@dictionaries.addons.mozilla.org
FF Extension: No Name - C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default\Extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
FF Extension: No Name - C:\Users\Drakuba\AppData\Roaming\Mozilla\Firefox\Profiles\xv1nymoe.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF HKLM\...\Firefox\Extensions: [
FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt
Chrome:
=======
CHR HomePage: hxxp://
www.delta-search.com/?babsrc=HP_ss&mntr ... 6&tsp=4933
CHR RestoreOnStartup: "hxxp://
www.delta-search.com/?babsrc=HP_ss&mntr ... 6&tsp=4933"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\24.0.1312.52\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Windows Genuine Advantage) - C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll (Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files\Battlelog Web Plugins\1.104.0\npesnlaunch.dll (ESN Social Software AB)
CHR Plugin: (ESN Launch Mozilla Plugin) - C:\Program Files\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
CHR Plugin: (ESN Sonar API) - C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
CHR Plugin: (WacomTabletPlugin) - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
CHR Plugin: (Uplay PC) - C:\Program Files\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll No File
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (Unity Player) - C:\Users\Drakuba\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
CHR Plugin: (Java Deployment Toolkit 7.0.210.11) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\Drakuba\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0
CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440392 2013-10-01] (Avira Operations GmbH & Co. KG)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 DES2 Service; C:\Program Files\GIGABYTE\EnergySaver2\des2svr.exe [68136 2009-06-17] ()
S4 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
R2 JMB36X; C:\Windows\System32\XSrvSetup.exe [72304 2010-01-19] ()
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [769432 2012-07-13] (Nero AG)
S4 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
S4 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-09-19] ()
R2 Smart TimeLock; C:\Program Files\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe [114688 2009-10-13] (Gigabyte Technology CO., LTD.)
S4 Sony PC Companion; C:\Program Files\Sony\Sony PC Companion\PCCService.exe [155320 2012-01-18] (Avanquest Software)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [1479488 2011-10-12] (TuneUp Software)
S4 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [528256 2012-12-11] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [19496 2010-04-27] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [278984 2013-07-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [89376 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-10-01] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-01] (Avira Operations GmbH & Co. KG)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R3 gdrv; C:\Windows\gdrv.sys [17488 2013-10-18] (Windows (R) 2000 DDK provider)
S3 GVTDrv; C:\Windows\system32\Drivers\GVTDrv.sys [24944 2011-09-29] ()
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 hidkmdf; C:\Windows\System32\DRIVERS\hidkmdf.sys [11680 2012-12-03] (Windows (R) Win 7 DDK provider)
R0 JRAID; C:\Windows\System32\DRIVERS\jraid.sys [98928 2010-01-27] (JMicron Technology Corp.)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-07-04] ()
R2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2009-07-20] (Realtek )
S3 RTTEAMPT; C:\Windows\System32\DRIVERS\RtTeam60.sys [43520 2009-12-21] (Realtek Corporation)
S3 RTVLANPT; C:\Windows\System32\DRIVERS\RtVlan60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation)
R3 SaiK0728; C:\Windows\System32\DRIVERS\SaiK0728.sys [104960 2008-02-18] (Saitek)
S3 SaiK0836; C:\Windows\System32\DRIVERS\SaiK0836.sys [107008 2008-09-12] (Saitek)
R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [23200 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [46624 2013-04-30] (Saitek)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [431672 2011-01-12] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-06-22] (Avira GmbH)
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [26112 2010-12-01] (The OpenVPN Project)
S3 TEAM; C:\Windows\System32\DRIVERS\RtTeam60.sys [43520 2009-12-21] (Realtek Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [10064 2011-09-22] (TuneUp Software)
S3 VLAN; C:\Windows\System32\DRIVERS\RtVLAN60.sys [19968 2007-12-03] (Windows (R) Codename Longhorn DDK provider)
S3 WacHidRouter; C:\Windows\System32\DRIVERS\wachidrouter.sys [70048 2012-12-03] (Wacom Technology)
S3 wacomrouterfilter; C:\Windows\System32\DRIVERS\wacomrouterfilter.sys [13728 2012-11-15] (Wacom Technology)
U3 awiu54kj; C:\Windows\System32\Drivers\awiu54kj.sys [0 ] (Advanced Micro Devices)
S3 catchme; \??\C:\Users\Drakuba\AppData\Local\Temp\catchme.sys [x]
S3 GMSIPCI; \??\F:\INSTALL\GMSIPCI.SYS [x]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [x]
S3 NTACCESS; \??\F:\NTACCESS.sys [x]
S3 NVHDA; system32\drivers\nvhda32v.sys [x]
S3 SetupNTGLM7X; \??\F:\NTGLM7X.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-18 13:26 - 2013-10-18 13:26 - 00000000 ____D C:\FRST
2013-10-18 13:21 - 2013-10-18 13:21 - 00112128 _____ (forum.viry.cz) C:\Users\Drakuba\Desktop\FRSTLauncher.exe
2013-10-18 13:19 - 2013-10-18 13:19 - 01087213 _____ (Farbar) C:\Users\Drakuba\Desktop\FRST.exe
2013-10-15 19:19 - 2013-10-15 19:19 - 00016896 _____ C:\Users\Drakuba\Desktop\PMA.xls
2013-10-13 06:20 - 2013-10-13 10:37 - 00000000 ____D C:\Users\Drakuba\Documents\Overlord
2013-10-12 12:21 - 2013-10-12 12:21 - 00000428 _____ C:\Users\Drakuba\Documents\telemetry.lsx
2013-10-12 11:46 - 2013-10-12 11:46 - 00000000 ____D C:\Users\Drakuba\Documents\Larian Studios
2013-10-09 08:23 - 2013-10-09 08:24 - 00000333 _____ C:\Users\Drakuba\Desktop\Nový textový dokument (3).TXT
2013-09-24 17:43 - 2013-09-24 17:43 - 00000000 ____D C:\Users\Drakuba\AppData\Local\FalloutNV
2013-09-23 18:07 - 2013-09-23 18:07 - 00000000 ____D C:\Program Files\Common Files\Java
2013-09-23 18:06 - 2013-09-23 18:06 - 00000000 ____D C:\ProgramData\Oracle
2013-09-23 18:05 - 2013-09-23 18:05 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-21 08:55 - 2013-09-21 08:55 - 00000000 ____D C:\Users\Drakuba\Documents\Telltale Games
2013-09-19 23:22 - 2013-09-19 23:22 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\dvdcss
2013-09-19 16:16 - 2013-09-19 16:16 - 00000000 ____D C:\ProgramData\Package Cache
==================== One Month Modified Files and Folders =======
2013-10-18 13:27 - 2011-01-01 04:37 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\uTorrent
2013-10-18 13:26 - 2013-10-18 13:26 - 00000000 ____D C:\FRST
2013-10-18 13:21 - 2013-10-18 13:21 - 00112128 _____ (forum.viry.cz) C:\Users\Drakuba\Desktop\FRSTLauncher.exe
2013-10-18 13:19 - 2013-10-18 13:19 - 01087213 _____ (Farbar) C:\Users\Drakuba\Desktop\FRST.exe
2013-10-18 12:54 - 2010-12-23 18:32 - 01603776 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-18 12:26 - 2009-07-14 06:34 - 00014864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-10-18 12:26 - 2009-07-14 06:34 - 00014864 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-10-18 12:19 - 2011-01-03 19:13 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\OpenOffice.org2
2013-10-18 12:18 - 2013-05-21 11:09 - 00024750 _____ C:\Windows\setupact.log
2013-10-18 12:18 - 2013-01-06 19:02 - 00000410 ____H C:\Windows\Tasks\OptimizerProUpdaterTask{E7548AB6-F971-4FB1-9C26-3B51B8AF60E6}.job
2013-10-18 12:18 - 2012-12-28 12:30 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-18 12:18 - 2011-01-04 11:48 - 00017488 _____ (Windows (R) 2000 DDK provider) C:\Windows\gdrv.sys
2013-10-18 12:18 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-18 11:57 - 2010-12-23 18:25 - 01070049 _____ C:\Windows\WindowsUpdate.log
2013-10-18 11:11 - 2010-12-28 22:20 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-10-18 01:35 - 2011-11-03 19:34 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\Skype
2013-10-15 19:19 - 2013-10-15 19:19 - 00016896 _____ C:\Users\Drakuba\Desktop\PMA.xls
2013-10-13 12:29 - 2011-01-08 23:04 - 00000000 ___RD C:\Users\Drakuba\Desktop\games
2013-10-13 10:37 - 2013-10-13 06:20 - 00000000 ____D C:\Users\Drakuba\Documents\Overlord
2013-10-12 12:21 - 2013-10-12 12:21 - 00000428 _____ C:\Users\Drakuba\Documents\telemetry.lsx
2013-10-12 11:46 - 2013-10-12 11:46 - 00000000 ____D C:\Users\Drakuba\Documents\Larian Studios
2013-10-11 12:24 - 2010-12-28 22:49 - 00000000 ____D C:\Program Files\Common Files\Steam
2013-10-09 08:24 - 2013-10-09 08:23 - 00000333 _____ C:\Users\Drakuba\Desktop\Nový textový dokument (3).TXT
2013-10-09 08:11 - 2009-07-14 04:37 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2013-10-08 14:57 - 2011-11-03 19:34 - 00000000 ____D C:\ProgramData\Skype
2013-10-01 13:01 - 2013-06-22 08:17 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-10-01 13:01 - 2013-06-22 02:12 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-10-01 13:01 - 2013-06-22 02:12 - 00089376 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-10-01 13:01 - 2013-06-22 02:12 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-09-29 08:05 - 2013-05-23 07:56 - 00012174 _____ C:\Windows\PFRO.log
2013-09-28 13:07 - 2012-01-29 00:20 - 00000000 ____D C:\Users\Drakuba\Documents\SavedGames
2013-09-28 12:53 - 2012-11-07 06:26 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\vlc
2013-09-25 10:09 - 2011-09-22 17:01 - 00000000 ____D C:\Users\Drakuba\KBCertifikat
2013-09-25 10:09 - 2010-12-23 18:29 - 00000000 ____D C:\Users\Drakuba
2013-09-24 17:43 - 2013-09-24 17:43 - 00000000 ____D C:\Users\Drakuba\AppData\Local\FalloutNV
2013-09-24 17:43 - 2010-12-23 23:51 - 00000000 ____D C:\Users\Drakuba\Documents\My Games
2013-09-23 18:07 - 2013-09-23 18:07 - 00000000 ____D C:\Program Files\Common Files\Java
2013-09-23 18:06 - 2013-09-23 18:06 - 00000000 ____D C:\ProgramData\Oracle
2013-09-23 18:05 - 2013-09-23 18:05 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2013-09-23 18:05 - 2012-09-30 21:09 - 00264616 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2013-09-23 18:05 - 2012-09-30 21:09 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2013-09-23 18:05 - 2012-09-30 21:09 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2013-09-23 18:05 - 2012-08-15 11:46 - 00868264 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll
2013-09-23 18:05 - 2010-12-28 20:07 - 00790440 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll
2013-09-23 18:04 - 2012-04-05 11:13 - 00000000 ____D C:\Program Files\Java
2013-09-23 16:42 - 2013-05-23 11:04 - 00000000 ___RD C:\Program Files\Skype
2013-09-23 09:09 - 2009-07-14 06:53 - 00032568 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-22 14:58 - 2013-09-02 12:35 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\3909
2013-09-22 14:48 - 2013-01-18 13:40 - 00290776 _____ C:\Windows\system32\PnkBstrB.exe
2013-09-22 14:48 - 2013-01-18 13:40 - 00139656 _____ C:\Windows\system32\Drivers\PnkBstrK.sys
2013-09-22 14:48 - 2010-12-24 12:29 - 00290776 _____ C:\Windows\system32\PnkBstrB.xtr
2013-09-21 08:55 - 2013-09-21 08:55 - 00000000 ____D C:\Users\Drakuba\Documents\Telltale Games
2013-09-21 08:55 - 2013-09-15 09:44 - 00000000 ____D C:\ProgramData\Steam
2013-09-20 15:49 - 2013-01-18 13:40 - 00290776 _____ C:\Windows\system32\PnkBstrB.ex0
2013-09-19 23:22 - 2013-09-19 23:22 - 00000000 ____D C:\Users\Drakuba\AppData\Roaming\dvdcss
2013-09-19 16:16 - 2013-09-19 16:16 - 00000000 ____D C:\ProgramData\Package Cache
2013-09-19 16:16 - 2010-12-24 12:28 - 00138904 _____ C:\Users\Drakuba\AppData\Roaming\PnkBstrK.sys
2013-09-19 16:15 - 2013-01-18 13:40 - 00076888 _____ C:\Windows\system32\PnkBstrA.exe
2013-09-18 00:21 - 2013-06-15 10:26 - 00000226 _____ C:\Users\Drakuba\Desktop\ENG.TXT
Files to move or delete:
====================
C:\ProgramData\hash.dat
Some content of TEMP:
====================
C:\Users\Drakuba\AppData\Local\Temp\avgnt.exe
C:\Users\Drakuba\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-13 15:22
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: () (Fixed) (Total:63.38 GB) (Free:11.1 GB) NTFS
Drive d: (Games) (Fixed) (Total:117.19 GB) (Free:3.13 GB) NTFS
Drive e: (Filmy) (Fixed) (Total:285.1 GB) (Free:2.18 GB) NTFS
Available physical RAM: 2163.69 MB
Total physical RAM: 3575.49 MB
Percentage of memory in use: 39%
==================== MBR and Partition Table ==================
Capsized
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 8C362353)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=63 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=117 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=285 GB) - (Type=07 NTFS)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\OptimizerProUpdaterTask{E7548AB6-F971-4FB1-9C26-3B51B8AF60E6}.job => C:\ProgramData\Premium\OptimizerPro\OptimizerPro.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 28_09_2013 (06)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Drakuba\Desktop" je 2624 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000000
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================