Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-09-2014
Ran by Elchappo (administrator) on ELCHAPPO-PC on 13-09-2014 01:18:12
Running from C:\Users\Elchappo\Desktop
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Logitech Inc.) C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) D:\Program Files\iTunes\iTunesHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Spotify Ltd) C:\Users\Elchappo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Blizzard Entertainment) D:\Program Files\Battle.net\Battle.net.4944\Battle.net.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.3346\Agent.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Blizzard Entertainment) D:\Program Files\World of Warcraft\Wow.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(Blizzard Entertainment) D:\Program Files\World of Warcraft\Utils\WowBrowserProxy.exe
(Google Inc.) C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\Elchappo\Desktop\FRSTLauncher (2).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [HP Software Update] => C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] => D:\Program Files\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\Run: [Google Update] => C:\Users\Elchappo\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2012-03-06] (Google Inc.)
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\Run: [] => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
pdate.exe" /c
(the data entry has 824 more characters).
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\Run: [Spotify Web Helper] => C:\Users\Elchappo\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1245752 2014-09-08] (Spotify Ltd)
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: I - I:\LaunchU3.exe -a
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {2805002e-87b5-11e1-9f13-001d60566c9f} - F:\Autorun.exe
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {28bcf242-419c-11e3-aa6b-001d60566c9f} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {376a693a-56ae-11e3-987f-001d60566c9f} - F:\Autorun\autorun.exe
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {c6278bc8-f78c-11e1-9652-001d60566c9f} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\EGO-wmv-480x360.wmv
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {ceea842c-782b-11e1-89e7-001d60566c9f} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1302123622-1747697599-3381875975-1001\...\MountPoints2: {eeb8599a-7cc2-11e1-8983-001d60566c9f} - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\EGO-wmv-480x360.wmv
Startup: C:\Users\Elchappo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
BootExecute: autocheck autochk * BootDefrag.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xAF39FB1DCAFECC01
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ie
SearchScopes: HKCU - {7B7E241A-FB41-47ED-94B0-2507226229E6} URL =
http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Elchappo\AppData\Roaming\Mozilla\Firefox\Profiles\nnrxp0t0.default
FF DefaultSearchEngine: ICQ Search
FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", "");
FF Homepage: user_pref("browser.startup.homepage", "");
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> D:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Elchappo\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\Elchappo\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: ditec.sk/DSigXadesFb -> C:\Program Files\Ditec\DSigXades\npDitec.Zep.DSigXadesFb.dll (Ditec,a.s.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin -> C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.google.com/
CHR StartupUrls: Default -> "about:blank"
CHR DefaultSearchKeyword: Default -> CAF8D4F2A7A4F2A0B2FC09A2948EFED500122098F76571A15F54986E2E4C4B01
CHR DefaultSearchURL: Default ->
https://mail.google.com/mail/?extsrc=mailto&url=%s
CHR CustomProfile: C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-03-06]
CHR Extension: (AdBlocker - Blokovač reklám pre YouTube™) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2013-11-04]
CHR Extension: (Hľadať v Google) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-03-06]
CHR Extension: (Top Eleven) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljphpjlafmmdmegmfbkacafhbegjfkkn [2013-10-07]
CHR Extension: (Pocket) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2014-02-27]
CHR Extension: (Save to Pocket) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2014-02-27]
CHR Extension: (Peňaženka Google) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-07]
CHR Extension: (Gmail) - C:\Users\Elchappo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-03-06]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx []
CHR StartMenuInternet: Google Chrome - C:\Users\Elchappo\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2013-07-18] (Teruten) [File not signed]
R2 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2011-03-04] (Hewlett-Packard Company) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Angelnt; C:\Windows\System32\Drivers\ANGELNT.SYS [51072 2014-02-25] (Identcode Ltd.) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2013-11-27] (Disc Soft Ltd)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-07-18] () [File not signed]
R3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2Mon.sys [25752 2009-10-07] ()
R3 LVUSBSta; C:\Windows\System32\drivers\LVUSBSta.sys [41752 2008-07-26] (Logitech Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NVFLASH; C:\Windows\system32\drivers\nvflash.sys [13344 2013-04-19] ()
S3 pepifilter; C:\Windows\System32\DRIVERS\lv302af.sys [13848 2008-07-26] (Logitech Inc.)
R3 PID_PEPI; C:\Windows\System32\DRIVERS\LV302V32.SYS [2570520 2008-07-26] (Logitech Inc.)
S3 USBAAPL; C:\Windows\System32\Drivers\usbaapl.sys [45056 2012-12-13] (Apple, Inc.) [File not signed]
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 01:18 - 2014-09-13 01:20 - 00014986 _____ () C:\Users\Elchappo\Desktop\FRST.txt
2014-09-13 01:17 - 2014-09-13 01:18 - 00000000 ____D () C:\FRST
2014-09-13 01:15 - 2014-09-13 01:14 - 00112640 _____ (forum.viry.cz) C:\Users\Elchappo\Desktop\FRSTLauncher (2).exe
2014-09-13 01:15 - 2014-09-13 01:12 - 01097728 _____ (Farbar) C:\Users\Elchappo\Desktop\FRST.exe
2014-09-11 19:30 - 2014-09-11 19:30 - 00001550 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-09-11 19:28 - 2014-09-11 19:28 - 00000000 ____D () C:\Program Files\iPod
2014-09-10 23:24 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-09-10 23:19 - 2014-09-10 23:17 - 01370467 _____ () C:\Users\Elchappo\Desktop\adwcleaner_3.309.exe
2014-09-10 23:18 - 2014-09-10 23:29 - 00000000 ____D () C:\AdwCleaner
2014-09-10 19:01 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-10 19:01 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-10 19:01 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-10 19:01 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-10 19:01 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-10 19:00 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-10 19:00 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-10 19:00 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-10 19:00 - 2014-08-18 23:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-10 19:00 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-10 19:00 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-10 19:00 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-10 19:00 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-10 19:00 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-10 19:00 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-10 19:00 - 2014-08-18 23:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-10 19:00 - 2014-08-18 23:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-10 19:00 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-10 19:00 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-10 19:00 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-10 19:00 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-10 19:00 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-10 19:00 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-10 19:00 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-10 19:00 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-10 19:00 - 2014-08-18 23:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-10 19:00 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-10 19:00 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-10 19:00 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-10 19:00 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-10 18:59 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-10 13:41 - 2014-09-10 13:41 - 10036224 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-10 11:26 - 2014-09-05 03:52 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-10 11:26 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-10 11:26 - 2014-07-07 03:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-10 11:26 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-10 11:26 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-10 11:25 - 2014-09-05 03:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-10 11:17 - 2014-09-13 00:59 - 00000336 _____ () C:\Windows\setupact.log
2014-09-10 11:17 - 2014-09-10 23:30 - 00001144 _____ () C:\Windows\PFRO.log
2014-09-10 11:17 - 2014-09-10 11:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-28 15:02 - 2014-08-23 03:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-28 15:02 - 2014-08-23 02:42 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-27 19:23 - 2014-08-27 19:24 - 00000262 _____ () C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2014-08-27 19:22 - 2014-08-27 19:22 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-25 08:37 - 2014-05-14 18:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-08-25 08:37 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-08-25 08:37 - 2014-05-14 18:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-08-25 08:37 - 2014-05-14 18:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-08-25 08:37 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-08-25 08:37 - 2014-05-14 18:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-08-25 08:37 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-08-25 08:37 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-08-25 08:37 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-08-24 11:41 - 2014-08-24 11:42 - 00000303 ____H () C:\Users\Elchappo\Documents\.picasa.ini
2014-08-24 11:14 - 2014-09-10 20:32 - 00000000 ____D () C:\Windows\rescache
2014-08-24 10:23 - 2014-08-24 10:23 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Oracle
2014-08-24 10:22 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-08-24 10:22 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-24 10:22 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-08-24 10:22 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-08-24 10:18 - 2014-08-24 10:18 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-24 10:17 - 2014-08-24 10:17 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-24 09:35 - 2014-07-14 03:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-24 09:35 - 2014-06-16 03:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-24 09:35 - 2014-06-16 03:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-08-24 09:35 - 2014-06-16 03:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-08-24 09:34 - 2014-07-16 04:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-08-24 09:34 - 2014-06-25 03:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-08-24 09:34 - 2014-06-03 11:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-24 09:34 - 2014-06-03 11:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-24 09:34 - 2014-06-03 11:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-24 09:34 - 2014-06-03 11:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 01:20 - 2014-09-13 01:18 - 00014986 _____ () C:\Users\Elchappo\Desktop\FRST.txt
2014-09-13 01:19 - 2013-10-27 21:45 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Battle.net
2014-09-13 01:18 - 2014-09-13 01:17 - 00000000 ____D () C:\FRST
2014-09-13 01:16 - 2012-03-06 18:17 - 01652024 _____ () C:\Windows\WindowsUpdate.log
2014-09-13 01:14 - 2014-09-13 01:15 - 00112640 _____ (forum.viry.cz) C:\Users\Elchappo\Desktop\FRSTLauncher (2).exe
2014-09-13 01:12 - 2014-09-13 01:15 - 01097728 _____ (Farbar) C:\Users\Elchappo\Desktop\FRST.exe
2014-09-13 01:07 - 2009-07-14 06:34 - 00015312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-13 01:07 - 2009-07-14 06:34 - 00015312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-13 01:06 - 2013-10-03 13:28 - 00000924 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-13 01:04 - 2012-03-06 18:35 - 01586846 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-13 01:01 - 2014-02-28 01:23 - 00000322 _____ () C:\Windows\Tasks\GlaryInitialize 4.job
2014-09-13 01:00 - 2013-10-03 13:28 - 00000920 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-13 00:59 - 2014-09-10 11:17 - 00000336 _____ () C:\Windows\setupact.log
2014-09-13 00:59 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-12 18:41 - 2012-04-11 15:35 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-12 18:30 - 2013-05-23 22:46 - 00000958 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302123622-1747697599-3381875975-1001UA.job
2014-09-12 18:04 - 2014-01-17 15:11 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Spotify
2014-09-12 17:46 - 2014-01-17 15:11 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Spotify
2014-09-12 16:53 - 2014-05-23 02:42 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Deployment
2014-09-12 12:07 - 2014-02-28 02:26 - 00000000 ____D () C:\Program Files\trend micro
2014-09-12 03:33 - 2013-10-07 16:12 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\BitTorrent
2014-09-12 02:21 - 2014-03-12 03:58 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\BSplayer PRO
2014-09-11 19:30 - 2014-09-11 19:30 - 00001550 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-09-11 19:28 - 2014-09-11 19:28 - 00000000 ____D () C:\Program Files\iPod
2014-09-11 19:28 - 2012-03-06 18:51 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-09-11 19:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-09-10 23:30 - 2014-09-10 11:17 - 00001144 _____ () C:\Windows\PFRO.log
2014-09-10 23:29 - 2014-09-10 23:18 - 00000000 ____D () C:\AdwCleaner
2014-09-10 23:27 - 2012-03-06 18:24 - 00000000 ____D () C:\Users\Elchappo
2014-09-10 23:17 - 2014-09-10 23:19 - 01370467 _____ () C:\Users\Elchappo\Desktop\adwcleaner_3.309.exe
2014-09-10 20:32 - 2014-08-24 11:14 - 00000000 ____D () C:\Windows\rescache
2014-09-10 18:59 - 2013-10-03 15:53 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-10 18:49 - 2012-03-09 02:42 - 98758480 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-10 18:49 - 2012-03-06 23:33 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-09-10 18:48 - 2014-05-06 19:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-09-10 18:48 - 2012-03-06 23:30 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-10 13:41 - 2014-09-10 13:41 - 10036224 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-09-10 13:41 - 2012-04-11 15:35 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-09-10 13:41 - 2012-03-12 02:24 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-09-10 11:17 - 2014-09-10 11:17 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-09 19:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-09 18:55 - 2012-03-06 18:53 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Apple Computer
2014-09-09 18:55 - 2012-03-06 18:53 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Apple Computer
2014-09-09 11:10 - 2014-03-08 22:48 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\DiskDefrag
2014-09-08 15:50 - 2014-01-22 16:16 - 00000000 ____D () C:\Users\Elchappo\Desktop\Blocky
2014-09-08 10:31 - 2014-07-07 08:34 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Adobe
2014-09-05 03:52 - 2014-09-10 11:26 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-09-05 03:47 - 2014-09-10 11:25 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-09-04 16:25 - 2012-03-06 19:02 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Skype
2014-09-04 00:07 - 2012-07-29 19:58 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Mumble
2014-08-29 13:04 - 2012-04-20 12:24 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\CrashDumps
2014-08-29 00:31 - 2009-07-14 06:33 - 00414840 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-27 19:24 - 2014-08-27 19:23 - 00000262 _____ () C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2014-08-27 19:22 - 2014-08-27 19:22 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-26 09:30 - 2013-05-23 22:46 - 00000906 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302123622-1747697599-3381875975-1001Core.job
2014-08-24 11:42 - 2014-08-24 11:41 - 00000303 ____H () C:\Users\Elchappo\Documents\.picasa.ini
2014-08-24 11:40 - 2012-03-06 18:34 - 00000000 ____D () C:\Users\Elchappo\AppData\Local\Google
2014-08-24 11:38 - 2012-03-10 21:07 - 00000000 ____D () C:\Program Files\Google
2014-08-24 10:23 - 2014-08-24 10:23 - 00000000 ____D () C:\Users\Elchappo\AppData\Roaming\Oracle
2014-08-24 10:18 - 2014-08-24 10:18 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-08-24 10:17 - 2014-08-24 10:17 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-24 10:17 - 2014-08-24 10:17 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-08-23 03:46 - 2014-08-28 15:02 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-23 02:42 - 2014-08-28 15:02 - 02352640 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-19 19:39 - 2014-09-10 19:00 - 00327872 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-19 00:26 - 2014-09-10 19:00 - 17455104 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-19 00:08 - 2014-09-10 19:00 - 04232704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-18 23:57 - 2014-09-10 19:01 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-18 23:57 - 2014-09-10 19:00 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-18 23:46 - 2014-09-10 19:00 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-18 23:45 - 2014-09-10 19:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-18 23:44 - 2014-09-10 19:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-18 23:44 - 2014-09-10 19:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-18 23:42 - 2014-09-10 19:00 - 02185728 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-18 23:39 - 2014-09-10 19:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-18 23:39 - 2014-09-10 19:00 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-18 23:37 - 2014-09-10 19:01 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-18 23:36 - 2014-09-10 19:00 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-18 23:36 - 2014-09-10 19:00 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-18 23:35 - 2014-09-10 19:01 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-18 23:30 - 2014-09-10 19:00 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-08-18 23:27 - 2014-09-10 19:00 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-18 23:22 - 2014-09-10 19:00 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-18 23:19 - 2014-09-10 19:00 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-18 23:17 - 2014-09-10 19:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-18 23:17 - 2014-09-10 19:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-18 23:15 - 2014-09-10 19:00 - 11769856 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-18 23:09 - 2014-09-10 19:00 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-18 23:08 - 2014-09-10 19:00 - 02014208 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-18 23:08 - 2014-09-10 19:00 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-18 23:07 - 2014-09-10 19:00 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-08-18 22:46 - 2014-09-10 19:00 - 01812992 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-18 22:38 - 2014-09-10 19:00 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-18 22:36 - 2014-09-10 19:00 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
Some content of TEMP:
====================
C:\Users\Elchappo\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GlaryInitialize 4.job => D:\Program Files\Glary Utilities 4\Initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302123622-1747697599-3381875975-1001Core.job => C:\Users\Elchappo\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302123622-1747697599-3381875975-1001UA.job => C:\Users\Elchappo\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
==================== Security Center ==================
AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1}
AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Elchappo\Desktop" je 7 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================