Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

kontrola prosim

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Soveren
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 23 led 2014 19:42

kontrola prosim

#1 Příspěvek od Soveren »

Zdravim prosim o kontrolu notase. Co se tyka win je 7 64 bit. Dekuji
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Toshiba (administrator) on TOSHIBA-TOSH on 05-04-2014 19:23:19
Running from C:\Users\Toshiba\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
(Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) c:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
() C:\Users\Toshiba\Desktop\RSITx64 (1).exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566696 2011-03-02] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [973176 2010-12-15] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2188904 2011-01-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-08] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] - C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-26] (Toshiba Europe GmbH)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] - c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG)
HKLM-x32\...\Run: [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-16] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1009288 2012-09-13] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-19\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [PCSpeedUp] - C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk [2223 2012-05-17] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Toshiba\AppData\Roaming\Seznam.cz\szninstall.exe [1009288 2012-09-13] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92152 2013-01-22] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-26] (Google Inc.)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {416d7bcf-4c18-11e2-a947-dc0ea1375269} - G:\Startme.exe
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {e6af17ab-9f65-11e1-9993-dc0ea1375269} - G:\autorun.exe
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=TEUA
SearchScopes: HKCU - DefaultScope {07A12968-065B-4899-970D-8CBDFB2DA562} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {07A12968-065B-4899-970D-8CBDFB2DA562} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {0C52265C-83DE-4763-ACA1-F9F6D9C07205} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {830FCA9B-91E8-457B-90A2-3B22B50896E0} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {88CEFABC-13C1-420D-9C03-FCC081A80FDA} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {C181B11E-3866-4C1D-8A6E-603097A12C82} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {C88A3E20-BF44-4A01-8AE0-D1FCE500630A} URL = http://www.firmy.cz/phr/{searchTerms}?s ... arch_12454
SearchScopes: HKCU - {E0B03FF6-C246-4ABA-ADEE-BA4EE74BEE99} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=12454
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\gcswf32.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-04-11]
CHR Extension: (Peněženka Google) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-07-01]

==================== Services (Whitelisted) =================

R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [821592 2012-01-09] (IObit)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-02-26] (LogMeIn, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [578264 2011-12-21] (Pandora.TV)
R2 PCSUService; C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe [235232 2011-11-07] ()
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [736104 2012-04-19] (Tunngle.net GmbH)

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-17] (DT Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation )
R2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [11376 2002-10-08] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-05 19:23 - 2014-04-05 19:23 - 00016579 _____ () C:\Users\Toshiba\Desktop\FRST.txt
2014-04-05 19:23 - 2014-04-05 19:23 - 00000000 ____D () C:\FRST
2014-04-05 19:22 - 2014-04-05 19:22 - 02157056 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\rsit
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\Program Files\trend micro
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Downloads\RSITx64.exe
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Desktop\RSITx64 (1).exe
2014-04-05 19:17 - 2014-04-05 19:17 - 00015327 _____ () C:\Users\Toshiba\Desktop\LM.bat
2014-04-05 19:13 - 2014-04-05 19:17 - 00029696 _____ () C:\Users\Toshiba\AppData\Local\MSGBOX.EXE
2014-04-05 19:12 - 2014-04-05 19:12 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 226489.crdownload
2014-04-05 19:11 - 2014-04-05 19:11 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 500129.crdownload
2014-04-05 19:08 - 2014-04-05 19:08 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Apple Computer
2014-04-04 21:09 - 2014-04-04 22:29 - 735881216 _____ () C:\Users\Toshiba\Downloads\Hele-vole,kdo-tu-vaří.avi
2014-04-02 18:37 - 2014-04-04 20:05 - 00000280 _____ () C:\Windows\setupact.log
2014-04-02 18:37 - 2014-04-02 18:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-01 20:18 - 2014-04-01 21:08 - 879667788 _____ () C:\Users\Toshiba\Downloads\01-02.Časy-se-mění-I,II.mp4
2014-04-01 19:04 - 2014-04-01 19:16 - 06041600 _____ () C:\Users\Toshiba\Desktop\BF2.exe
2014-03-31 21:21 - 2014-03-31 22:12 - 798182529 _____ () C:\Users\Toshiba\Downloads\21-22.Ztracené-město-I,II.mp4
2014-03-31 19:09 - 2014-03-31 19:18 - 160154549 _____ () C:\Users\Toshiba\Downloads\sg1-08x12-Upoutany_Prometheus_-_Prometheus_unbound.mp4
2014-03-30 19:51 - 2014-03-30 21:21 - 738013872 _____ () C:\Users\Toshiba\Downloads\Nerikej.ani.slovo.2001.DVDRip.XviD.CZ_xvid.avi
2014-03-30 12:34 - 2014-03-30 12:44 - 180322017 _____ () C:\Users\Toshiba\Downloads\sg1-07x12-Evoluce-2cast_-_Evolution-part2.mp4
2014-03-29 18:52 - 2014-03-29 19:41 - 730769408 _____ () C:\Users\Toshiba\Downloads\delta_force-cz.avi
2014-03-24 20:49 - 2014-03-24 22:54 - 1184031579 _____ () C:\Users\Toshiba\Downloads\Skandální-odhalení---Disclosure-(1994)---CZ.mkv
2014-03-23 13:49 - 2014-03-23 14:36 - 368494592 _____ () C:\Users\Toshiba\Downloads\Stargate-SG-1_-05x04---Pátý-člen.avi
2014-03-21 19:39 - 2014-03-21 20:18 - 641331200 _____ () C:\Users\Toshiba\Downloads\Disciples-2-CD1.iso
2014-03-17 16:34 - 2014-03-17 18:15 - 857538560 _____ () C:\Users\Toshiba\Downloads\MALY-KOUSEK-NEBE---CZ-dvdrip.avi
2014-03-17 11:59 - 2014-03-17 12:13 - 222861879 _____ () C:\Users\Toshiba\Downloads\sg1-02x20-Neviditelny_nepritel_-_Show_and_tell.mp4
2014-03-17 11:55 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-17 11:55 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-17 11:55 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-16 19:29 - 2014-03-16 19:29 - 00002111 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-03-16 19:29 - 2014-03-16 19:29 - 00002089 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-03-15 18:32 - 2014-03-15 22:13 - 2077442048 _____ () C:\Users\Toshiba\Downloads\Battlefield-2.iso
2014-03-15 18:17 - 2014-03-15 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Skype
2014-03-15 18:16 - 2014-03-15 18:17 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-15 18:16 - 2014-03-15 18:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-14 20:02 - 2014-03-14 20:02 - 00094208 _____ (Blizzard Entertainment) C:\Windows\DIIUnin.exe
2014-03-14 20:02 - 2014-03-14 20:02 - 00017951 _____ () C:\Windows\DIIUnin.dat
2014-03-14 20:02 - 2014-03-14 20:02 - 00002829 _____ () C:\Windows\DIIUnin.pif
2014-03-14 20:02 - 2014-03-14 20:02 - 00001908 _____ () C:\Users\Public\Desktop\Diablo II.lnk
2014-03-14 20:01 - 2014-03-15 19:05 - 00000000 ____D () C:\Program Files (x86)\Diablo II
2014-03-14 18:50 - 2014-03-14 19:21 - 520949760 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Install-by-kepytkepyt.iso
2014-03-14 18:10 - 2014-03-14 18:44 - 610064384 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Play-by-kepytkepyt.iso
2014-03-13 16:10 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 16:10 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 16:10 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 16:10 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 16:10 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 16:10 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 16:10 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 16:10 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 16:10 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 16:10 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 16:10 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 16:10 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 16:10 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 16:10 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 16:10 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 16:10 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 16:10 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 16:10 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 16:10 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 16:10 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 16:10 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 16:10 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 16:10 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 16:10 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 16:10 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 16:10 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 16:10 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 16:10 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 16:10 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 16:10 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 16:10 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 16:10 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 16:10 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 16:10 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 16:10 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 16:10 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 16:10 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 16:10 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 16:10 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 16:10 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 16:10 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 16:10 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 16:10 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 16:08 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 16:08 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-10 18:32 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-03-10 18:32 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-09 17:33 - 2014-03-09 17:52 - 00000000 ____D () C:\Users\Toshiba\Desktop\Lionel Richie
2014-03-07 21:57 - 2014-03-07 22:25 - 375459840 _____ () C:\Users\Toshiba\Downloads\Stargate_SG1_-_08x13_-_Je_dobre_byt_kralem.avi
2014-03-06 20:33 - 2014-03-06 21:01 - 386204868 _____ () C:\Users\Toshiba\Downloads\Stargate-Atlantis---01x09---Domov-(by-Monterra).avi

==================== One Month Modified Files and Folders =======

2014-04-05 19:23 - 2014-04-05 19:23 - 00016579 _____ () C:\Users\Toshiba\Desktop\FRST.txt
2014-04-05 19:23 - 2014-04-05 19:23 - 00000000 ____D () C:\FRST
2014-04-05 19:22 - 2014-04-05 19:22 - 02157056 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\rsit
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\Program Files\trend micro
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Downloads\RSITx64.exe
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Desktop\RSITx64 (1).exe
2014-04-05 19:17 - 2014-04-05 19:17 - 00015327 _____ () C:\Users\Toshiba\Desktop\LM.bat
2014-04-05 19:17 - 2014-04-05 19:13 - 00029696 _____ () C:\Users\Toshiba\AppData\Local\MSGBOX.EXE
2014-04-05 19:12 - 2014-04-05 19:12 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 226489.crdownload
2014-04-05 19:11 - 2014-04-05 19:11 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 500129.crdownload
2014-04-05 19:08 - 2014-04-05 19:08 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Apple Computer
2014-04-05 19:08 - 2011-12-07 19:06 - 01364537 _____ () C:\Windows\WindowsUpdate.log
2014-04-05 19:06 - 2012-03-29 15:01 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Skype
2014-04-05 19:00 - 2012-04-12 11:38 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 18:59 - 2012-06-21 22:29 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\LogMeIn Hamachi
2014-04-05 18:59 - 2011-08-26 12:34 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-05 18:59 - 2011-08-26 12:34 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-05 13:01 - 2011-02-14 10:37 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-04-05 13:01 - 2011-02-14 10:37 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-04-05 13:01 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-05 12:00 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-05 12:00 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-04 22:29 - 2014-04-04 21:09 - 735881216 _____ () C:\Users\Toshiba\Downloads\Hele-vole,kdo-tu-vaří.avi
2014-04-04 20:05 - 2014-04-02 18:37 - 00000280 _____ () C:\Windows\setupact.log
2014-04-02 20:21 - 2013-03-17 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\vlc
2014-04-02 20:01 - 2013-07-22 20:49 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\dvdcss
2014-04-02 18:37 - 2014-04-02 18:37 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-01 21:08 - 2014-04-01 20:18 - 879667788 _____ () C:\Users\Toshiba\Downloads\01-02.Časy-se-mění-I,II.mp4
2014-04-01 19:16 - 2014-04-01 19:04 - 06041600 _____ () C:\Users\Toshiba\Desktop\BF2.exe
2014-04-01 17:18 - 2013-07-19 12:11 - 00000000 ____D () C:\Windows\Minidump
2014-04-01 17:18 - 2012-05-17 15:25 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\DAEMON Tools Lite
2014-04-01 16:54 - 2012-01-05 20:39 - 00000000 ____D () C:\Users\Toshiba
2014-04-01 15:19 - 2013-03-17 17:41 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Seznam.cz
2014-04-01 15:13 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-31 22:41 - 2012-05-16 17:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-31 22:41 - 2012-05-16 17:50 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-31 22:41 - 2012-05-16 17:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-31 22:12 - 2014-03-31 21:21 - 798182529 _____ () C:\Users\Toshiba\Downloads\21-22.Ztracené-město-I,II.mp4
2014-03-31 19:18 - 2014-03-31 19:09 - 160154549 _____ () C:\Users\Toshiba\Downloads\sg1-08x12-Upoutany_Prometheus_-_Prometheus_unbound.mp4
2014-03-30 21:21 - 2014-03-30 19:51 - 738013872 _____ () C:\Users\Toshiba\Downloads\Nerikej.ani.slovo.2001.DVDRip.XviD.CZ_xvid.avi
2014-03-30 18:52 - 2011-08-26 12:34 - 00003962 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-30 18:52 - 2011-08-26 12:34 - 00003710 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-30 12:44 - 2014-03-30 12:34 - 180322017 _____ () C:\Users\Toshiba\Downloads\sg1-07x12-Evoluce-2cast_-_Evolution-part2.mp4
2014-03-29 19:41 - 2014-03-29 18:52 - 730769408 _____ () C:\Users\Toshiba\Downloads\delta_force-cz.avi
2014-03-29 18:22 - 2012-03-20 13:44 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Google
2014-03-24 22:54 - 2014-03-24 20:49 - 1184031579 _____ () C:\Users\Toshiba\Downloads\Skandální-odhalení---Disclosure-(1994)---CZ.mkv
2014-03-23 14:36 - 2014-03-23 13:49 - 368494592 _____ () C:\Users\Toshiba\Downloads\Stargate-SG-1_-05x04---Pátý-člen.avi
2014-03-23 00:30 - 2013-07-02 22:47 - 00003078 _____ () C:\Windows\System32\Tasks\Game_Booster_Startup
2014-03-21 20:18 - 2014-03-21 19:39 - 641331200 _____ () C:\Users\Toshiba\Downloads\Disciples-2-CD1.iso
2014-03-17 18:15 - 2014-03-17 16:34 - 857538560 _____ () C:\Users\Toshiba\Downloads\MALY-KOUSEK-NEBE---CZ-dvdrip.avi
2014-03-17 12:13 - 2014-03-17 11:59 - 222861879 _____ () C:\Users\Toshiba\Downloads\sg1-02x20-Neviditelny_nepritel_-_Show_and_tell.mp4
2014-03-17 12:00 - 2013-07-15 15:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-17 11:56 - 2012-05-18 14:11 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 11:48 - 2009-07-14 06:45 - 00420584 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-17 00:11 - 2012-10-06 16:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-16 19:38 - 2012-06-21 21:57 - 00000000 ____D () C:\Users\Toshiba\Documents\Battlefield 2
2014-03-16 19:29 - 2014-03-16 19:29 - 00002111 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-03-16 19:29 - 2014-03-16 19:29 - 00002089 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-03-16 19:28 - 2012-06-21 21:57 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2014-03-16 19:28 - 2012-06-21 21:57 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
2014-03-16 19:23 - 2011-08-26 11:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-15 22:13 - 2014-03-15 18:32 - 2077442048 _____ () C:\Users\Toshiba\Downloads\Battlefield-2.iso
2014-03-15 19:08 - 2012-08-24 12:21 - 00000000 ____D () C:\Users\Toshiba\Desktop\FreeRapid-0.85u1
2014-03-15 19:05 - 2014-03-14 20:01 - 00000000 ____D () C:\Program Files (x86)\Diablo II
2014-03-15 18:17 - 2014-03-15 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Skype
2014-03-15 18:17 - 2014-03-15 18:16 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-15 18:17 - 2011-08-26 12:13 - 00000000 ____D () C:\ProgramData\Skype
2014-03-15 18:16 - 2014-03-15 18:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-15 17:09 - 2011-08-26 12:35 - 00002190 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-14 23:57 - 2013-06-30 22:36 - 00000000 ____D () C:\Program Files (x86)\Warcraft III
2014-03-14 20:02 - 2014-03-14 20:02 - 00094208 _____ (Blizzard Entertainment) C:\Windows\DIIUnin.exe
2014-03-14 20:02 - 2014-03-14 20:02 - 00017951 _____ () C:\Windows\DIIUnin.dat
2014-03-14 20:02 - 2014-03-14 20:02 - 00002829 _____ () C:\Windows\DIIUnin.pif
2014-03-14 20:02 - 2014-03-14 20:02 - 00001908 _____ () C:\Users\Public\Desktop\Diablo II.lnk
2014-03-14 19:31 - 2012-08-30 12:49 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 19:31 - 2012-08-30 12:49 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 19:31 - 2012-08-30 12:49 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 19:21 - 2014-03-14 18:50 - 520949760 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Install-by-kepytkepyt.iso
2014-03-14 18:44 - 2014-03-14 18:10 - 610064384 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Play-by-kepytkepyt.iso
2014-03-12 19:28 - 2012-04-12 11:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 19:28 - 2012-04-12 11:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-12 19:28 - 2012-04-12 11:38 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-11 09:52 - 2011-04-27 15:25 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys
2014-03-10 21:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-03-09 17:52 - 2014-03-09 17:33 - 00000000 ____D () C:\Users\Toshiba\Desktop\Lionel Richie
2014-03-09 17:52 - 2013-11-05 22:13 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Mp3tag
2014-03-08 23:46 - 2013-06-08 23:22 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Mumble
2014-03-07 22:25 - 2014-03-07 21:57 - 375459840 _____ () C:\Users\Toshiba\Downloads\Stargate_SG1_-_08x13_-_Je_dobre_byt_kralem.avi
2014-03-06 21:01 - 2014-03-06 20:33 - 386204868 _____ () C:\Users\Toshiba\Downloads\Stargate-Atlantis---01x09---Domov-(by-Monterra).avi

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 19:31

==================== End Of Log ============================
http://leteckaposta.cz/672605465

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119536
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola prosim

#2 Příspěvek od Rudy »

Také zdravím!
Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-26] (Google Inc.)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {416d7bcf-4c18-11e2-a947-dc0ea1375269} - G:\Startme.exe
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {e6af17ab-9f65-11e1-9993-dc0ea1375269} - G:\autorun.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
C:\Program Files (x86)\Google\Google Toolbar
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Soveren
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 23 led 2014 19:42

Re: kontrola prosim

#3 Příspěvek od Soveren »

dekuji za rychlou odpoved zde je log
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
Ran by Toshiba at 2014-04-05 20:43:27 Run:1
Running from C:\Users\Toshiba\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
Start
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-08-26] (Google Inc.)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {416d7bcf-4c18-11e2-a947-dc0ea1375269} - G:\Startme.exe
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {e6af17ab-9f65-11e1-9993-dc0ea1375269} - G:\autorun.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
C:\Program Files (x86)\Google\Google Toolbar
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
End
*****************

HKU\S-1-5-21-1266210591-2655401262-749206315-1000\Software\Microsoft\Windows\CurrentVersion\Run\\swg => Value deleted successfully.
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{416d7bcf-4c18-11e2-a947-dc0ea1375269} => Key deleted successfully.
HKCR\CLSID\{416d7bcf-4c18-11e2-a947-dc0ea1375269} => Key not found.
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e6af17ab-9f65-11e1-9993-dc0ea1375269} => Key deleted successfully.
HKCR\CLSID\{e6af17ab-9f65-11e1-9993-dc0ea1375269} => Key not found.
C:\Program Files (x86)\Google\GoogleToolbarNotifier => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7} => Key deleted successfully.
HKCR\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7} => Key deleted successfully.
C:\Program Files (x86)\Google\Google Toolbar => Moved successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => Key deleted successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\Wow6432Node\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F} => Key deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Value deleted successfully.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => Key not found.
C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll not found.
C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll not found.
c:\progra~2\mcafee\msc\npmcsn~1.dll not found.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => Moved successfully.
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => Moved successfully.

==== End of Fixlog ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119536
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola prosim

#4 Příspěvek od Rudy »

Smazáno. FRST je možné smazat.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Soveren
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 23 led 2014 19:42

Re: kontrola prosim

#5 Příspěvek od Soveren »

dekuji.a nejaky dalsi chyby, nebo nejaky necistoty v notasu nejsou ?
Uz je cistej ?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119536
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola prosim

#6 Příspěvek od Rudy »

Ještě vymeteme dočasné soubory. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Soveren
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 23 led 2014 19:42

Re: kontrola prosim

#7 Příspěvek od Soveren »

dekuji zde je log
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Toshiba (administrator) on TOSHIBA-TOSH on 05-04-2014 22:36:48
Running from C:\Users\Toshiba\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
() C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Pandora.TV) C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(IObit) C:\Program Files (x86)\IObit\Game Booster 3\gbtray.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(TOSHIBA) C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe
() C:\Users\Toshiba\AppData\Roaming\Seznam.cz\szninstall.exe
(Toshiba) C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
(Intel Corporation) C:\Windows\system32\igfxext.exe
() C:\Users\Toshiba\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [TosNC] - C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597928 2011-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] - C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-12-14] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] - C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1546720 2011-02-10] (Toshiba Europe GmbH)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [566696 2011-03-02] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [973176 2010-12-15] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11776104 2011-02-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2188904 2011-01-18] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2679592 2011-02-03] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710040 2010-12-08] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] - C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe [150992 2011-08-26] (Toshiba Europe GmbH)
HKLM\...\Run: [MSC] - c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] - c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe [1409424 2011-06-29] (Nero AG)
HKLM-x32\...\Run: [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [532480 2010-11-09] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2010-03-04] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34160 2010-08-16] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [seznam-listicka-distribuce] - C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1009288 2012-09-13] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-19\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-20\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [TOPI.EXE] - C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [846936 2011-05-16] (TOSHIBA)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3671872 2012-04-17] (DT Soft Ltd)
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [PCSpeedUp] - C:\Program Files (x86)\Zrychleni Pocitace\PCSpeedUp.lnk [2223 2012-05-17] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [cz.seznam.software.autoupdate] - C:\Users\Toshiba\AppData\Roaming\Seznam.cz\szninstall.exe [1009288 2012-09-13] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\Run: [cz.seznam.software.szndesktop] - C:\Users\Toshiba\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92152 2013-01-22] ()
HKU\S-1-5-21-1266210591-2655401262-749206315-1000\...\MountPoints2: {e6af17ab-9f65-11e1-9993-dc0ea1375269} - G:\autorun.exe
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain ... &bmod=TEUA
SearchScopes: HKCU - DefaultScope {07A12968-065B-4899-970D-8CBDFB2DA562} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {07A12968-065B-4899-970D-8CBDFB2DA562} URL = http://search.seznam.cz/?q={searchTerms ... arch_12454
SearchScopes: HKCU - {0C52265C-83DE-4763-ACA1-F9F6D9C07205} URL = http://encyklopedie.seznam.cz/search?q= ... arch_12454
SearchScopes: HKCU - {830FCA9B-91E8-457B-90A2-3B22B50896E0} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {88CEFABC-13C1-420D-9C03-FCC081A80FDA} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_12454
SearchScopes: HKCU - {C181B11E-3866-4C1D-8A6E-603097A12C82} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_12454
SearchScopes: HKCU - {C88A3E20-BF44-4A01-8AE0-D1FCE500630A} URL = http://www.firmy.cz/phr/{searchTerms}?s ... arch_12454
SearchScopes: HKCU - {E0B03FF6-C246-4ABA-ADEE-BA4EE74BEE99} URL = http://www.mapy.cz/?query={searchTerms} ... arch_12454
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/?clid=12454
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\gcswf32.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\McChPlg.dll No File
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (McAfee SecurityCenter) - c:\progra~2\mcafee\msc\npmcsn~1.dll No File
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2013-04-11]
CHR Extension: (Peněženka Google) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Toshiba\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2013-07-01]

==================== Services (Whitelisted) =================

R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1809920 2010-08-04] (Realsil Microelectronics Inc.)
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [821592 2012-01-09] (IObit)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-02-26] (LogMeIn, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe [578264 2011-12-21] (Pandora.TV)
R2 PCSUService; C:\Program Files (x86)\Zrychleni Pocitace\PCSUService.exe [235232 2011-11-07] ()
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [736104 2012-04-19] (Tunngle.net GmbH)

==================== Drivers (Whitelisted) ====================

R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-05-17] (DT Soft Ltd)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [1514568 2013-05-02] (Realtek Semiconductor Corporation )
R2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [11376 2002-10-08] ()
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-05 22:35 - 2014-04-05 22:35 - 00000926 _____ () C:\Windows\PFRO.log
2014-04-05 22:33 - 2014-04-05 22:33 - 00000000 ____D () C:\_OTM
2014-04-05 22:31 - 2014-04-05 22:31 - 00522240 _____ (OldTimer Tools) C:\Users\Toshiba\Desktop\OTM.exe
2014-04-05 20:50 - 2014-04-05 22:35 - 00000168 _____ () C:\Windows\setupact.log
2014-04-05 20:50 - 2014-04-05 20:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-05 19:23 - 2014-04-05 22:36 - 00014990 _____ () C:\Users\Toshiba\Desktop\FRST.txt
2014-04-05 19:23 - 2014-04-05 22:36 - 00000000 ____D () C:\FRST
2014-04-05 19:22 - 2014-04-05 19:22 - 02157056 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\rsit
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\Program Files\trend micro
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Downloads\RSITx64.exe
2014-04-05 19:17 - 2014-04-05 19:17 - 00015327 _____ () C:\Users\Toshiba\Desktop\LM.bat
2014-04-05 19:13 - 2014-04-05 19:17 - 00029696 _____ () C:\Users\Toshiba\AppData\Local\MSGBOX.EXE
2014-04-05 19:12 - 2014-04-05 19:12 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 226489.crdownload
2014-04-05 19:11 - 2014-04-05 19:11 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 500129.crdownload
2014-04-05 19:08 - 2014-04-05 19:08 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Apple Computer
2014-04-04 21:09 - 2014-04-04 22:29 - 735881216 _____ () C:\Users\Toshiba\Downloads\Hele-vole,kdo-tu-vaří.avi
2014-04-01 20:18 - 2014-04-01 21:08 - 879667788 _____ () C:\Users\Toshiba\Downloads\01-02.Časy-se-mění-I,II.mp4
2014-04-01 19:04 - 2014-04-01 19:16 - 06041600 _____ () C:\Users\Toshiba\Desktop\BF2.exe
2014-03-31 21:21 - 2014-03-31 22:12 - 798182529 _____ () C:\Users\Toshiba\Downloads\21-22.Ztracené-město-I,II.mp4
2014-03-31 19:09 - 2014-03-31 19:18 - 160154549 _____ () C:\Users\Toshiba\Downloads\sg1-08x12-Upoutany_Prometheus_-_Prometheus_unbound.mp4
2014-03-30 19:51 - 2014-03-30 21:21 - 738013872 _____ () C:\Users\Toshiba\Downloads\Nerikej.ani.slovo.2001.DVDRip.XviD.CZ_xvid.avi
2014-03-30 12:34 - 2014-03-30 12:44 - 180322017 _____ () C:\Users\Toshiba\Downloads\sg1-07x12-Evoluce-2cast_-_Evolution-part2.mp4
2014-03-29 18:52 - 2014-03-29 19:41 - 730769408 _____ () C:\Users\Toshiba\Downloads\delta_force-cz.avi
2014-03-24 20:49 - 2014-03-24 22:54 - 1184031579 _____ () C:\Users\Toshiba\Downloads\Skandální-odhalení---Disclosure-(1994)---CZ.mkv
2014-03-23 13:49 - 2014-03-23 14:36 - 368494592 _____ () C:\Users\Toshiba\Downloads\Stargate-SG-1_-05x04---Pátý-člen.avi
2014-03-21 19:39 - 2014-03-21 20:18 - 641331200 _____ () C:\Users\Toshiba\Downloads\Disciples-2-CD1.iso
2014-03-17 16:34 - 2014-03-17 18:15 - 857538560 _____ () C:\Users\Toshiba\Downloads\MALY-KOUSEK-NEBE---CZ-dvdrip.avi
2014-03-17 11:59 - 2014-03-17 12:13 - 222861879 _____ () C:\Users\Toshiba\Downloads\sg1-02x20-Neviditelny_nepritel_-_Show_and_tell.mp4
2014-03-17 11:55 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-17 11:55 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-17 11:55 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-16 19:29 - 2014-03-16 19:29 - 00002111 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-03-16 19:29 - 2014-03-16 19:29 - 00002089 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-03-15 18:32 - 2014-03-15 22:13 - 2077442048 _____ () C:\Users\Toshiba\Downloads\Battlefield-2.iso
2014-03-15 18:17 - 2014-03-15 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Skype
2014-03-15 18:16 - 2014-03-15 18:17 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-15 18:16 - 2014-03-15 18:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-14 20:02 - 2014-03-14 20:02 - 00094208 _____ (Blizzard Entertainment) C:\Windows\DIIUnin.exe
2014-03-14 20:02 - 2014-03-14 20:02 - 00017951 _____ () C:\Windows\DIIUnin.dat
2014-03-14 20:02 - 2014-03-14 20:02 - 00002829 _____ () C:\Windows\DIIUnin.pif
2014-03-14 20:02 - 2014-03-14 20:02 - 00001908 _____ () C:\Users\Public\Desktop\Diablo II.lnk
2014-03-14 20:01 - 2014-03-15 19:05 - 00000000 ____D () C:\Program Files (x86)\Diablo II
2014-03-14 18:50 - 2014-03-14 19:21 - 520949760 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Install-by-kepytkepyt.iso
2014-03-14 18:10 - 2014-03-14 18:44 - 610064384 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Play-by-kepytkepyt.iso
2014-03-13 16:10 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 16:10 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 16:10 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 16:10 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 16:10 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 16:10 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 16:10 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 16:10 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 16:10 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 16:10 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 16:10 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 16:10 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 16:10 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 16:10 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 16:10 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 16:10 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 16:10 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 16:10 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 16:10 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 16:10 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 16:10 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 16:10 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 16:10 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 16:10 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 16:10 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 16:10 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 16:10 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 16:10 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 16:10 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 16:10 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 16:10 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 16:10 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 16:10 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 16:10 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 16:10 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 16:10 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 16:10 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 16:10 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 16:10 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 16:10 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 16:10 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 16:10 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 16:10 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 16:08 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 16:08 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-10 18:32 - 2014-01-09 04:22 - 05694464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-03-10 18:32 - 2014-01-04 00:44 - 06574592 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-03-09 17:33 - 2014-04-05 20:43 - 00000000 ____D () C:\Users\Toshiba\Desktop\Lionel Richie
2014-03-07 21:57 - 2014-03-07 22:25 - 375459840 _____ () C:\Users\Toshiba\Downloads\Stargate_SG1_-_08x13_-_Je_dobre_byt_kralem.avi
2014-03-06 20:33 - 2014-03-06 21:01 - 386204868 _____ () C:\Users\Toshiba\Downloads\Stargate-Atlantis---01x09---Domov-(by-Monterra).avi

==================== One Month Modified Files and Folders =======

2014-04-05 22:37 - 2014-04-05 19:23 - 00014990 _____ () C:\Users\Toshiba\Desktop\FRST.txt
2014-04-05 22:36 - 2014-04-05 19:23 - 00000000 ____D () C:\FRST
2014-04-05 22:35 - 2014-04-05 22:35 - 00000926 _____ () C:\Windows\PFRO.log
2014-04-05 22:35 - 2014-04-05 20:50 - 00000168 _____ () C:\Windows\setupact.log
2014-04-05 22:35 - 2012-06-21 22:29 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\LogMeIn Hamachi
2014-04-05 22:35 - 2011-08-26 12:34 - 00000966 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-05 22:35 - 2011-08-26 12:34 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-05 22:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-05 22:34 - 2011-12-07 19:06 - 01365681 _____ () C:\Windows\WindowsUpdate.log
2014-04-05 22:33 - 2014-04-05 22:33 - 00000000 ____D () C:\_OTM
2014-04-05 22:31 - 2014-04-05 22:31 - 00522240 _____ (OldTimer Tools) C:\Users\Toshiba\Desktop\OTM.exe
2014-04-05 22:31 - 2012-03-29 15:01 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Skype
2014-04-05 22:00 - 2012-04-12 11:38 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 20:50 - 2014-04-05 20:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-05 20:43 - 2014-03-09 17:33 - 00000000 ____D () C:\Users\Toshiba\Desktop\Lionel Richie
2014-04-05 20:43 - 2011-08-26 12:34 - 00000000 ____D () C:\Program Files (x86)\Google
2014-04-05 19:22 - 2014-04-05 19:22 - 02157056 _____ (Farbar) C:\Users\Toshiba\Desktop\FRST64.exe
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\rsit
2014-04-05 19:19 - 2014-04-05 19:19 - 00000000 ____D () C:\Program Files\trend micro
2014-04-05 19:18 - 2014-04-05 19:18 - 00935175 _____ () C:\Users\Toshiba\Downloads\RSITx64.exe
2014-04-05 19:17 - 2014-04-05 19:17 - 00015327 _____ () C:\Users\Toshiba\Desktop\LM.bat
2014-04-05 19:17 - 2014-04-05 19:13 - 00029696 _____ () C:\Users\Toshiba\AppData\Local\MSGBOX.EXE
2014-04-05 19:12 - 2014-04-05 19:12 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 226489.crdownload
2014-04-05 19:11 - 2014-04-05 19:11 - 00112640 _____ (forum.viry.cz) C:\Users\Toshiba\Downloads\Nepotvrzeno 500129.crdownload
2014-04-05 19:08 - 2014-04-05 19:08 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Apple Computer
2014-04-05 13:01 - 2011-02-14 10:37 - 00669132 _____ () C:\Windows\system32\perfh005.dat
2014-04-05 13:01 - 2011-02-14 10:37 - 00141760 _____ () C:\Windows\system32\perfc005.dat
2014-04-05 13:01 - 2009-07-14 07:13 - 01584626 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-05 12:00 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-05 12:00 - 2009-07-14 06:45 - 00025120 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-04 22:29 - 2014-04-04 21:09 - 735881216 _____ () C:\Users\Toshiba\Downloads\Hele-vole,kdo-tu-vaří.avi
2014-04-02 20:21 - 2013-03-17 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\vlc
2014-04-02 20:01 - 2013-07-22 20:49 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\dvdcss
2014-04-01 21:08 - 2014-04-01 20:18 - 879667788 _____ () C:\Users\Toshiba\Downloads\01-02.Časy-se-mění-I,II.mp4
2014-04-01 19:16 - 2014-04-01 19:04 - 06041600 _____ () C:\Users\Toshiba\Desktop\BF2.exe
2014-04-01 17:18 - 2013-07-19 12:11 - 00000000 ____D () C:\Windows\Minidump
2014-04-01 17:18 - 2012-05-17 15:25 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\DAEMON Tools Lite
2014-04-01 16:54 - 2012-01-05 20:39 - 00000000 ____D () C:\Users\Toshiba
2014-04-01 15:19 - 2013-03-17 17:41 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Seznam.cz
2014-03-31 22:41 - 2012-05-16 17:51 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-31 22:41 - 2012-05-16 17:50 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-03-31 22:41 - 2012-05-16 17:50 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-03-31 22:12 - 2014-03-31 21:21 - 798182529 _____ () C:\Users\Toshiba\Downloads\21-22.Ztracené-město-I,II.mp4
2014-03-31 19:18 - 2014-03-31 19:09 - 160154549 _____ () C:\Users\Toshiba\Downloads\sg1-08x12-Upoutany_Prometheus_-_Prometheus_unbound.mp4
2014-03-30 21:21 - 2014-03-30 19:51 - 738013872 _____ () C:\Users\Toshiba\Downloads\Nerikej.ani.slovo.2001.DVDRip.XviD.CZ_xvid.avi
2014-03-30 12:44 - 2014-03-30 12:34 - 180322017 _____ () C:\Users\Toshiba\Downloads\sg1-07x12-Evoluce-2cast_-_Evolution-part2.mp4
2014-03-29 19:41 - 2014-03-29 18:52 - 730769408 _____ () C:\Users\Toshiba\Downloads\delta_force-cz.avi
2014-03-29 18:22 - 2012-03-20 13:44 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Google
2014-03-24 22:54 - 2014-03-24 20:49 - 1184031579 _____ () C:\Users\Toshiba\Downloads\Skandální-odhalení---Disclosure-(1994)---CZ.mkv
2014-03-23 14:36 - 2014-03-23 13:49 - 368494592 _____ () C:\Users\Toshiba\Downloads\Stargate-SG-1_-05x04---Pátý-člen.avi
2014-03-23 00:30 - 2013-07-02 22:47 - 00003078 _____ () C:\Windows\System32\Tasks\Game_Booster_Startup
2014-03-21 20:18 - 2014-03-21 19:39 - 641331200 _____ () C:\Users\Toshiba\Downloads\Disciples-2-CD1.iso
2014-03-17 18:15 - 2014-03-17 16:34 - 857538560 _____ () C:\Users\Toshiba\Downloads\MALY-KOUSEK-NEBE---CZ-dvdrip.avi
2014-03-17 12:13 - 2014-03-17 11:59 - 222861879 _____ () C:\Users\Toshiba\Downloads\sg1-02x20-Neviditelny_nepritel_-_Show_and_tell.mp4
2014-03-17 12:00 - 2013-07-15 15:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-17 11:56 - 2012-05-18 14:11 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 11:48 - 2009-07-14 06:45 - 00420584 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-17 00:11 - 2012-10-06 16:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-16 19:38 - 2012-06-21 21:57 - 00000000 ____D () C:\Users\Toshiba\Documents\Battlefield 2
2014-03-16 19:29 - 2014-03-16 19:29 - 00002111 _____ () C:\Users\Public\Desktop\Play BF2 Online Now!.lnk
2014-03-16 19:29 - 2014-03-16 19:29 - 00002089 _____ () C:\Users\Public\Desktop\Battlefield 2.lnk
2014-03-16 19:28 - 2012-06-21 21:57 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2014-03-16 19:28 - 2012-06-21 21:57 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
2014-03-16 19:23 - 2011-08-26 11:59 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-15 22:13 - 2014-03-15 18:32 - 2077442048 _____ () C:\Users\Toshiba\Downloads\Battlefield-2.iso
2014-03-15 19:08 - 2012-08-24 12:21 - 00000000 ____D () C:\Users\Toshiba\Desktop\FreeRapid-0.85u1
2014-03-15 19:05 - 2014-03-14 20:01 - 00000000 ____D () C:\Program Files (x86)\Diablo II
2014-03-15 18:17 - 2014-03-15 18:17 - 00000000 ____D () C:\Users\Toshiba\AppData\Local\Skype
2014-03-15 18:17 - 2014-03-15 18:16 - 00002731 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-15 18:17 - 2011-08-26 12:13 - 00000000 ____D () C:\ProgramData\Skype
2014-03-15 18:16 - 2014-03-15 18:16 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-15 17:09 - 2011-08-26 12:35 - 00002190 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-03-14 23:57 - 2013-06-30 22:36 - 00000000 ____D () C:\Program Files (x86)\Warcraft III
2014-03-14 20:02 - 2014-03-14 20:02 - 00094208 _____ (Blizzard Entertainment) C:\Windows\DIIUnin.exe
2014-03-14 20:02 - 2014-03-14 20:02 - 00017951 _____ () C:\Windows\DIIUnin.dat
2014-03-14 20:02 - 2014-03-14 20:02 - 00002829 _____ () C:\Windows\DIIUnin.pif
2014-03-14 20:02 - 2014-03-14 20:02 - 00001908 _____ () C:\Users\Public\Desktop\Diablo II.lnk
2014-03-14 19:31 - 2012-08-30 12:49 - 00021840 ____T () C:\Windows\SysWOW64\SIntfNT.dll
2014-03-14 19:31 - 2012-08-30 12:49 - 00017212 ____T () C:\Windows\SysWOW64\SIntf32.dll
2014-03-14 19:31 - 2012-08-30 12:49 - 00012067 ____T () C:\Windows\SysWOW64\SIntf16.dll
2014-03-14 19:21 - 2014-03-14 18:50 - 520949760 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Install-by-kepytkepyt.iso
2014-03-14 18:44 - 2014-03-14 18:10 - 610064384 _____ () C:\Users\Toshiba\Downloads\Diablo-2-Play-by-kepytkepyt.iso
2014-03-12 19:28 - 2012-04-12 11:38 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 19:28 - 2012-04-12 11:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-12 19:28 - 2012-04-12 11:38 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-11 09:52 - 2011-04-27 15:25 - 00133928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NisDrvWFP.sys
2014-03-10 21:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-03-09 17:52 - 2013-11-05 22:13 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Mp3tag
2014-03-08 23:46 - 2013-06-08 23:22 - 00000000 ____D () C:\Users\Toshiba\AppData\Roaming\Mumble
2014-03-07 22:25 - 2014-03-07 21:57 - 375459840 _____ () C:\Users\Toshiba\Downloads\Stargate_SG1_-_08x13_-_Je_dobre_byt_kralem.avi
2014-03-06 21:01 - 2014-03-06 20:33 - 386204868 _____ () C:\Users\Toshiba\Downloads\Stargate-Atlantis---01x09---Domov-(by-Monterra).avi

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-03-30 19:31

==================== End Of Log ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119536
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola prosim

#8 Příspěvek od Rudy »

OK. Pokud není nějaký problém, je to vše.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Soveren
Návštěvník
Návštěvník
Příspěvky: 73
Registrován: 23 led 2014 19:42

Re: kontrola prosim

#9 Příspěvek od Soveren »

ok dekuji to je vse. Preji hezky vecer a este jednou dekuji

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119536
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: kontrola prosim

#10 Příspěvek od Rudy »

I vám hezký den a nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno