Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Mara (administrator) on MARA-PC on 06-11-2014 18:22:24
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
() C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe
() C:\Program Files\PodoWeb\updatePodoWeb.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe
() C:\Program Files\PodoWeb\bin\utilPodoWeb.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Dropbox, Inc.) C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.PurBrowse.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BrowserAdapter.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASPRT.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOAS.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASPRT.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOAS.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASPRT.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOAS.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASPRT.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOAS.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOASPRT.exe
() C:\Program Files\PodoWeb\bin\PodoWeb.BOAS.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Clarus Drive Manager] => C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe [8135744 2013-12-18] (Clarus, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mara\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\RunOnce: [FlashPlayerUpdate] => C:\Windows\system32\Macromed\Flash\FlashUtil32_15_0_0_152_Plugin.exe [854192 2014-09-11] (Adobe Systems Incorporated)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\MountPoints2: {821a1baa-4260-11e4-87bc-4061860b4475} - E:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
SearchScopes: HKCU - {009E31A3-65AA-49C9-BDF1-297A28EB7A39} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {0BAAC8FB-A908-4FD1-851C-1F205F594A5B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {524F2895-365C-491D-BCE7-E7B7AC140CDE} URL = http://search.seznam.cz/?q={searchTerms ... arch_13415
SearchScopes: HKCU - {68A5BFC4-EBDF-40D5-B718-CCD2DA9B9351} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {6B960334-B635-420F-8A58-E72BAA545D30} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {7E0446E9-C847-4829-921A-EAD3FC3DA028} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {88801F01-7AA0-4D76-A8D3-E03DF2ADACCE} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {9001FC15-9197-48FB-82E9-ACB9AA928779} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A85BD942-F40A-4D2E-8EDD-8AE90F46D353} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: PodoWeb -> {980b8a8f-ea0b-4c24-a2e9-70635e2502e9} -> C:\Program Files\PodoWeb\PodoWebbho.dll (PodoWeb)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Noia Fox options - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-11-06]
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-06]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Disk Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (PodoWeb) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo [2014-10-21]
CHR Extension: (Skype Click to Call) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-23]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 MaintainerSvc6.89.573444; C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321\maintainer.exe [123632 2014-11-06] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 SZDrvSvc; C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe [18432 2013-12-18] (Clarus, Inc.) [File not signed]
R2 Update PodoWeb; C:\Program Files\PodoWeb\updatePodoWeb.exe [525552 2002-01-01] ()
R2 Util PodoWeb; C:\Program Files\PodoWeb\bin\utilPodoWeb.exe [525552 2014-11-06] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 mdf16; C:\Program Files\Clarus\Samsung Drive Manager\mdf16.sys [18864 2012-06-21] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl27b055d9; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsl27b055d9.sys [39464 2014-11-06] (Microsoft Corporation)
R1 MpKsldc8000f0; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsldc8000f0.sys [39464 2014-11-06] (Microsoft Corporation)
R3 mvd23; C:\Program Files\Clarus\Samsung Drive Manager\mvd23.sys [89008 2012-06-21] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-04] (NVIDIA Corporation)
R3 TrdCap; C:\Windows\System32\DRIVERS\TrdCap.sys [1554472 2010-06-09] (Trident Microsystems, Inc.)
R1 {00c97d86-accb-4288-9972-6d929c1fe93a}Gw; C:\Windows\System32\drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw.sys [43144 2014-10-21] (StdLib)
R1 {19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw; C:\Windows\System32\drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw.sys [43144 2014-10-27] (StdLib)
R1 {51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw; C:\Windows\System32\drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw.sys [43144 2014-11-03] (StdLib)
R1 {972b8ad0-9d6f-4688-9227-759df6914df4}Gw; C:\Windows\System32\drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw.sys [43144 2014-10-22] (StdLib)
R1 {a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw; C:\Windows\System32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw.sys [43144 2014-11-04] (StdLib)
R1 {d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw; C:\Windows\System32\drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw.sys [43144 2014-10-30] (StdLib)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 18:20 - 2014-11-06 18:22 - 00023147 _____ () C:\Users\Mara\Desktop\Addition.txt
2014-11-06 18:17 - 2014-11-06 18:23 - 00017064 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-11-06 18:17 - 2014-11-06 18:22 - 00000000 ____D () C:\FRST
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Downloads\FRSTLauncher.exe
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Downloads\FRST.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Desktop\FRST.exe
2014-11-06 18:14 - 2014-11-06 18:14 - 00112107 _____ (forum.viry.cz) C:\Users\Mara\Downloads\VerzeOS.exe
2014-11-06 18:09 - 2014-11-06 18:09 - 175903298 _____ () C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe.part
2014-11-06 18:09 - 2014-11-06 18:09 - 00000000 _____ () C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe
2014-11-06 17:47 - 2014-11-06 18:00 - 355092040 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner.exe
2014-11-06 17:43 - 2014-11-06 17:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-06 17:37 - 2014-11-06 17:37 - 00000000 ____D () C:\Users\Mara\Desktop\Původní data aplikace Firefox
2014-11-06 15:41 - 2002-01-01 00:11 - 554374476 _____ () C:\Users\Mara\Downloads\12-let-v-řetězech-CZ-DABING-(2013).avi
2014-11-06 13:05 - 2014-11-06 13:05 - 00000000 ____D () C:\Zaloha
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-06 12:57 - 2014-11-06 12:57 - 04974864 _____ (Piriform Ltd) C:\Users\Mara\Downloads\ccsetup419.exe
2014-11-06 12:57 - 2014-11-06 12:57 - 00384529 _____ () C:\Users\Mara\Downloads\Lista_centrum.exe
2014-11-06 12:56 - 2014-11-06 12:56 - 00733352 _____ () C:\Users\Mara\Downloads\ccleaner-lista-centrumcz.exe
2014-11-04 18:46 - 2014-11-04 06:40 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw.sys
2014-11-04 18:45 - 2014-11-04 18:45 - 00000000 ____D () C:\Users\Mara\AppData\Local\Clarus
2014-11-03 19:22 - 2014-11-03 04:47 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{51d6aaf3-0bd7-47b0-8963-1c6f4d58b8fd}Gw.sys
2014-10-30 17:33 - 2014-10-30 04:15 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{d04f5c84-12ff-4486-8e31-240e7ca6e6d3}Gw.sys
2014-10-28 13:22 - 2014-11-06 15:37 - 00000000 ____D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-27 17:06 - 2014-10-27 07:33 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{19b94dbb-e67e-43ec-827b-c943f0fc9c16}Gw.sys
2014-10-23 15:16 - 2014-10-23 15:16 - 00000000 ____D () C:\Users\Mara\Desktop\Sygic
2014-10-23 14:18 - 2014-10-23 14:34 - 156473215 _____ () C:\Users\Mara\Downloads\Sygic-13.4.2-(HUD-+-mapy-03.2014-+-navod).rar
2014-10-23 08:40 - 2014-10-22 21:32 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{972b8ad0-9d6f-4688-9227-759df6914df4}Gw.sys
2014-10-22 18:36 - 2014-10-22 18:36 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-10-21 17:21 - 2014-10-21 04:01 - 00043144 _____ (StdLib) C:\Windows\system32\Drivers\{00c97d86-accb-4288-9972-6d929c1fe93a}Gw.sys
2014-10-20 15:21 - 2014-11-06 18:04 - 00000000 ____D () C:\Program Files\PodoWeb
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-10-20 15:20 - 2013-04-05 20:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm.new
2014-10-20 15:19 - 2014-11-06 17:08 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-10-20 15:19 - 2014-10-20 15:21 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Advanced
2014-10-20 15:19 - 2014-10-20 15:19 - 00000000 ____D () C:\Program Files\Shark007
2014-10-20 15:18 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Advanced
2014-10-20 15:18 - 2014-10-20 15:18 - 18037228 _____ () C:\Users\Mara\Downloads\K-Lite_Codec_Pack_Basic.exe
2014-10-20 15:16 - 2014-10-20 15:18 - 51374363 _____ () C:\Users\Mara\Downloads\ADVANCED_Codecs_v473.exe
2014-10-20 15:11 - 2014-10-20 15:11 - 00000000 ____D () C:\Users\Mara\AppData\Local\{D2D3C1DA-D502-41DC-B218-2E869514E44A}
2014-10-20 15:11 - 2014-10-20 15:11 - 00000000 ____D () C:\Users\Mara\AppData\Local\{650D7AEE-9B0B-4C0E-B460-3E1386BBAB6D}
2014-10-19 18:40 - 2014-10-19 18:40 - 13429504 _____ (Disc Soft Ltd) C:\Users\Mara\Downloads\DTLite4491-0356.exe
2014-10-14 20:13 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 20:13 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 20:13 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 20:12 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 20:12 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 20:12 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 20:12 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 20:12 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 20:12 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 20:12 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 20:12 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 20:12 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 20:12 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 20:12 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 20:12 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 20:12 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 20:12 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 20:12 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 20:12 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 20:12 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 20:12 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 20:12 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 20:12 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 20:12 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 20:12 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 20:12 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 20:12 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 20:12 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 20:12 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 20:12 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 20:12 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 20:09 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 20:09 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 20:09 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-14 20:09 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-14 20:09 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-14 20:09 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-14 20:09 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-14 20:09 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-14 20:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-14 20:09 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-14 20:08 - 2014-08-19 03:40 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 20:08 - 2014-08-19 03:40 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 20:08 - 2014-08-19 02:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-14 20:08 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-14 20:08 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-14 20:08 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-14 20:08 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-14 20:08 - 2014-07-07 02:28 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-14 20:08 - 2014-06-28 01:21 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-14 19:57 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Mara\Desktop\Nová složka
2014-10-14 18:30 - 2014-10-14 18:30 - 02059865 _____ () C:\Users\Mara\Downloads\cpu-z_1.70-en.zip
2014-10-13 14:26 - 2014-10-13 14:28 - 29555583 _____ () C:\Users\Mara\Downloads\Pitbull-Ft.-John-Ryan---Fireball.flac
2014-10-10 18:49 - 2014-10-10 19:05 - 00000000 ____D () C:\Users\Mara\AppData\Local\Microsoft Games
2014-10-09 17:03 - 2014-10-04 16:21 - 00000000 ____D () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW
2014-10-09 17:02 - 1970-01-01 00:59 - 74162521 ____N () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW.rar
2014-10-08 17:20 - 2014-10-08 17:20 - 00000993 _____ () C:\Users\Mara\Desktop\MediaCoder.lnk
2014-10-08 17:20 - 2014-10-08 17:20 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:20 - 00000000 ____D () C:\Program Files\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:19 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Broad Intelligence
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 18:18 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 18:18 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 17:44 - 2014-09-22 18:05 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Skype
2014-11-06 17:44 - 2014-09-11 17:11 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 17:43 - 2014-09-10 08:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-06 17:38 - 2014-09-09 09:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-06 17:30 - 2014-09-09 09:19 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 17:08 - 2014-09-08 14:41 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 17:06 - 2014-09-08 14:36 - 02027740 _____ () C:\Windows\WindowsUpdate.log
2014-11-06 17:04 - 2014-09-11 10:05 - 00000000 ___RD () C:\Users\Mara\Dropbox
2014-11-06 17:04 - 2014-09-11 10:01 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Dropbox
2014-11-06 17:04 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-11-06 17:03 - 2014-09-09 09:19 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 17:03 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 17:03 - 2002-01-01 00:01 - 00000112 _____ () C:\Windows\setupact.log
2014-11-06 13:03 - 2014-10-04 13:19 - 00000000 ____D () C:\Windows\Minidump
2014-11-06 13:03 - 2014-09-08 15:26 - 00000000 ____D () C:\Windows\Panther
2014-10-30 12:24 - 2014-09-09 09:23 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-24 01:10 - 2014-09-11 15:41 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\vlc
2014-10-21 18:21 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-10-20 15:11 - 2014-09-09 09:48 - 00000000 ____D () C:\Users\Mara\AppData\Local\Windows Live
2014-10-18 20:38 - 2014-09-22 18:05 - 00000000 ____D () C:\ProgramData\Skype
2014-10-15 03:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-15 02:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-15 02:42 - 2009-07-14 05:33 - 00337296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 02:32 - 2014-09-09 10:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 02:15 - 2014-09-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 02:12 - 2014-09-09 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 02:04 - 2014-09-09 10:04 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Mara\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfkuhfz.dll
C:\Users\Mara\AppData\Local\Temp\~7586.exe
C:\Users\Mara\AppData\Local\Temp\~C2A.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
Prosim o kontrolu logu
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Re: Prosim o kontrolu logu
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.6 (11.05.2014:1)
OS: Windows 7 Home Premium x86
Ran by Mara on źt 06.11.2014 at 19:14:57,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524F2895-365C-491D-BCE7-E7B7AC140CDE}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Mara\appdata\local\{650D7AEE-9B0B-4C0E-B460-3E1386BBAB6D}
Successfully deleted: [Empty Folder] C:\Users\Mara\appdata\local\{D2D3C1DA-D502-41DC-B218-2E869514E44A}
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 06.11.2014 at 19:17:35,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.6 (11.05.2014:1)
OS: Windows 7 Home Premium x86
Ran by Mara on źt 06.11.2014 at 19:14:57,01
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{524F2895-365C-491D-BCE7-E7B7AC140CDE}
~~~ Files
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Mara\appdata\local\{650D7AEE-9B0B-4C0E-B460-3E1386BBAB6D}
Successfully deleted: [Empty Folder] C:\Users\Mara\appdata\local\{D2D3C1DA-D502-41DC-B218-2E869514E44A}
~~~ Chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on źt 06.11.2014 at 19:17:35,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Re: Prosim o kontrolu logu
pořád mi vyskakuji reklamy 
log je tady..
# AdwCleaner v3.311 - Report created 06/11/2014 at 19:22:27
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Mara - MARA-PC
# Running from : C:\Users\Mara\Desktop\adwcleaner_3.311.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Update PodoWeb
[#] Service Deleted : Util PodoWeb
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\PodoWeb
Folder Deleted : C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo
File Deleted : C:\Windows\system32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw.sys
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatePodoWeb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatePodoWeb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilPodoWeb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilPodoWeb_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update PodoWeb
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util PodoWeb
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AEDAB5B0-022B-465C-A88B-1E8C2FAAA5A2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{b3d6b511-4d77-44db-a459-938d9e6995f7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\PodoWeb
Key Deleted : HKLM\SOFTWARE\PodoWeb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PodoWeb
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.0.2 (x86 cs)
[ File : C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\prefs.js ]
-\\ Google Chrome v38.0.2125.111
[ File : C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3498 octets] - [06/11/2014 19:20:34]
AdwCleaner[S0].txt - [2922 octets] - [06/11/2014 19:22:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2982 octets] ##########
log je tady..
# AdwCleaner v3.311 - Report created 06/11/2014 at 19:22:27
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)
# Username : Mara - MARA-PC
# Running from : C:\Users\Mara\Desktop\adwcleaner_3.311.exe
# Option : Clean
***** [ Services ] *****
[#] Service Deleted : Update PodoWeb
[#] Service Deleted : Util PodoWeb
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files\PodoWeb
Folder Deleted : C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo
File Deleted : C:\Windows\system32\drivers\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}Gw.sys
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatePodoWeb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\updatePodoWeb_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilPodoWeb_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\utilPodoWeb_RASMANCS
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Update PodoWeb
Key Deleted : HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Util PodoWeb
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AEDAB5B0-022B-465C-A88B-1E8C2FAAA5A2}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{b3d6b511-4d77-44db-a459-938d9e6995f7}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{980b8a8f-ea0b-4c24-a2e9-70635e2502e9}
Key Deleted : HKCU\Software\PodoWeb
Key Deleted : HKLM\SOFTWARE\PodoWeb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PodoWeb
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17344
-\\ Mozilla Firefox v33.0.2 (x86 cs)
[ File : C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\prefs.js ]
-\\ Google Chrome v38.0.2125.111
[ File : C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [3498 octets] - [06/11/2014 19:20:34]
AdwCleaner[S0].txt - [2922 octets] - [06/11/2014 19:22:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2982 octets] ##########
Re: Prosim o kontrolu logu
ani nevim kde
a to mam nove preistalovany PC (ty okna sou fakt na nervy)
tady je log.... diky
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Mara (administrator) on MARA-PC on 06-11-2014 19:38:10
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
() C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe
(Dropbox, Inc.) C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Clarus Drive Manager] => C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe [8135744 2013-12-18] (Clarus, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mara\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\MountPoints2: {821a1baa-4260-11e4-87bc-4061860b4475} - E:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
SearchScopes: HKCU - {009E31A3-65AA-49C9-BDF1-297A28EB7A39} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {0BAAC8FB-A908-4FD1-851C-1F205F594A5B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {68A5BFC4-EBDF-40D5-B718-CCD2DA9B9351} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {6B960334-B635-420F-8A58-E72BAA545D30} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {7E0446E9-C847-4829-921A-EAD3FC3DA028} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {88801F01-7AA0-4D76-A8D3-E03DF2ADACCE} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {9001FC15-9197-48FB-82E9-ACB9AA928779} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A85BD942-F40A-4D2E-8EDD-8AE90F46D353} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Noia Fox options - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-11-06]
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: PodoWeb - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi [2014-11-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-06]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Disk Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (PodoWeb) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo [2014-10-21]
CHR Extension: (Skype Click to Call) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-23]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 SZDrvSvc; C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe [18432 2013-12-18] (Clarus, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 mdf16; C:\Program Files\Clarus\Samsung Drive Manager\mdf16.sys [18864 2012-06-21] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl237535bf; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsl237535bf.sys [39464 2014-11-06] (Microsoft Corporation)
R3 mvd23; C:\Program Files\Clarus\Samsung Drive Manager\mvd23.sys [89008 2012-06-21] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-04] (NVIDIA Corporation)
R3 TrdCap; C:\Windows\System32\DRIVERS\TrdCap.sys [1554472 2010-06-09] (Trident Microsystems, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-11-06 19:20 - 2014-11-06 19:22 - 00000000 ____D () C:\AdwCleaner
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Downloads\adwcleaner_3.311.exe
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Desktop\adwcleaner_3.311.exe
2014-11-06 19:17 - 2014-11-06 19:17 - 00001133 _____ () C:\Users\Mara\Desktop\JRT.txt
2014-11-06 19:14 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Desktop\JRT.exe
2014-11-06 19:14 - 2014-11-06 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-11-06 19:13 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Downloads\JRT.exe
2014-11-06 18:41 - 2014-11-06 18:52 - 00021578 _____ () C:\Users\Mara\Desktop\Nmc_2014-11-06_18-41-36.log
2014-11-06 18:40 - 2014-11-06 18:40 - 00000000 ____D () C:\Users\Mara\AppData\Local\Norman Malware Cleaner
2014-11-06 18:27 - 2014-11-06 18:27 - 00006695 _____ () C:\Users\Mara\Desktop\Addition.rar
2014-11-06 18:20 - 2014-11-06 18:25 - 00023146 _____ () C:\Users\Mara\Desktop\Addition.txt
2014-11-06 18:17 - 2014-11-06 19:38 - 00014613 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-11-06 18:17 - 2014-11-06 19:38 - 00000000 ____D () C:\FRST
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Downloads\FRSTLauncher.exe
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Downloads\FRST.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Desktop\FRST.exe
2014-11-06 18:14 - 2014-11-06 18:14 - 00112107 _____ (forum.viry.cz) C:\Users\Mara\Downloads\VerzeOS.exe
2014-11-06 18:09 - 2014-11-06 18:38 - 360763416 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe
2014-11-06 17:47 - 2014-11-06 18:00 - 355092040 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner.exe
2014-11-06 17:43 - 2014-11-06 17:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-06 17:37 - 2014-11-06 17:37 - 00000000 ____D () C:\Users\Mara\Desktop\Původní data aplikace Firefox
2014-11-06 15:41 - 2002-01-01 00:11 - 554374476 _____ () C:\Users\Mara\Downloads\12-let-v-řetězech-CZ-DABING-(2013).avi
2014-11-06 13:05 - 2014-11-06 13:05 - 00000000 ____D () C:\Zaloha
2014-11-06 12:58 - 2014-11-06 18:45 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-06 12:57 - 2014-11-06 12:57 - 04974864 _____ (Piriform Ltd) C:\Users\Mara\Downloads\ccsetup419.exe
2014-11-06 12:57 - 2014-11-06 12:57 - 00384529 _____ () C:\Users\Mara\Downloads\Lista_centrum.exe
2014-11-06 12:56 - 2014-11-06 12:56 - 00733352 _____ () C:\Users\Mara\Downloads\ccleaner-lista-centrumcz.exe
2014-11-04 18:45 - 2014-11-04 18:45 - 00000000 ____D () C:\Users\Mara\AppData\Local\Clarus
2014-10-28 13:22 - 2014-11-06 18:47 - 00000000 ____D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-23 15:16 - 2014-10-23 15:16 - 00000000 ____D () C:\Users\Mara\Desktop\Sygic
2014-10-23 14:18 - 2014-10-23 14:34 - 156473215 _____ () C:\Users\Mara\Downloads\Sygic-13.4.2-(HUD-+-mapy-03.2014-+-navod).rar
2014-10-22 18:36 - 2014-10-22 18:36 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-10-20 15:20 - 2013-04-05 20:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm.new
2014-10-20 15:19 - 2014-11-06 19:29 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-10-20 15:19 - 2014-10-20 15:21 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Advanced
2014-10-20 15:19 - 2014-10-20 15:19 - 00000000 ____D () C:\Program Files\Shark007
2014-10-20 15:18 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Advanced
2014-10-20 15:18 - 2014-10-20 15:18 - 18037228 _____ () C:\Users\Mara\Downloads\K-Lite_Codec_Pack_Basic.exe
2014-10-20 15:16 - 2014-10-20 15:18 - 51374363 _____ () C:\Users\Mara\Downloads\ADVANCED_Codecs_v473.exe
2014-10-19 18:40 - 2014-10-19 18:40 - 13429504 _____ (Disc Soft Ltd) C:\Users\Mara\Downloads\DTLite4491-0356.exe
2014-10-14 20:13 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 20:13 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 20:13 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 20:12 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 20:12 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 20:12 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 20:12 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 20:12 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 20:12 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 20:12 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 20:12 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 20:12 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 20:12 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 20:12 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 20:12 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 20:12 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 20:12 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 20:12 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 20:12 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 20:12 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 20:12 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 20:12 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 20:12 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 20:12 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 20:12 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 20:12 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 20:12 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 20:12 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 20:12 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 20:12 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 20:12 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 20:09 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 20:09 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 20:09 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-14 20:09 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-14 20:09 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-14 20:09 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-14 20:09 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-14 20:09 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-14 20:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-14 20:09 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-14 20:08 - 2014-08-19 03:40 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 20:08 - 2014-08-19 03:40 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 20:08 - 2014-08-19 02:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-14 20:08 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-14 20:08 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-14 20:08 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-14 20:08 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-14 20:08 - 2014-07-07 02:28 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-14 20:08 - 2014-06-28 01:21 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-14 19:57 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Mara\Desktop\Nová složka
2014-10-14 18:30 - 2014-10-14 18:30 - 02059865 _____ () C:\Users\Mara\Downloads\cpu-z_1.70-en.zip
2014-10-13 14:26 - 2014-10-13 14:28 - 29555583 _____ () C:\Users\Mara\Downloads\Pitbull-Ft.-John-Ryan---Fireball.flac
2014-10-10 18:49 - 2014-10-10 19:05 - 00000000 ____D () C:\Users\Mara\AppData\Local\Microsoft Games
2014-10-09 17:03 - 2014-10-04 16:21 - 00000000 ____D () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW
2014-10-09 17:02 - 1970-01-01 00:59 - 74162521 ____N () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW.rar
2014-10-08 17:20 - 2014-10-08 17:20 - 00000993 _____ () C:\Users\Mara\Desktop\MediaCoder.lnk
2014-10-08 17:20 - 2014-10-08 17:20 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:20 - 00000000 ____D () C:\Program Files\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:19 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Broad Intelligence
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:31 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 19:31 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 19:30 - 2014-09-09 09:19 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 19:30 - 2014-09-08 14:41 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 19:29 - 2014-09-08 14:36 - 02035086 _____ () C:\Windows\WindowsUpdate.log
2014-11-06 19:25 - 2014-09-11 10:05 - 00000000 ___RD () C:\Users\Mara\Dropbox
2014-11-06 19:25 - 2014-09-11 10:01 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Dropbox
2014-11-06 19:24 - 2014-09-22 18:05 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Skype
2014-11-06 19:24 - 2014-09-10 08:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-06 19:24 - 2014-09-09 09:19 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 19:24 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 19:24 - 2002-01-01 00:01 - 00002348 _____ () C:\Windows\PFRO.log
2014-11-06 19:24 - 2002-01-01 00:01 - 00000168 _____ () C:\Windows\setupact.log
2014-11-06 19:16 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-11-06 18:44 - 2014-09-11 17:11 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 17:38 - 2014-09-09 09:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-06 13:03 - 2014-10-04 13:19 - 00000000 ____D () C:\Windows\Minidump
2014-11-06 13:03 - 2014-09-08 15:26 - 00000000 ____D () C:\Windows\Panther
2014-10-30 12:24 - 2014-09-09 09:23 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-24 01:10 - 2014-09-11 15:41 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\vlc
2014-10-21 18:21 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-10-20 15:11 - 2014-09-09 09:48 - 00000000 ____D () C:\Users\Mara\AppData\Local\Windows Live
2014-10-18 20:38 - 2014-09-22 18:05 - 00000000 ____D () C:\ProgramData\Skype
2014-10-15 03:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-15 02:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-15 02:42 - 2009-07-14 05:33 - 00337296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 02:32 - 2014-09-09 10:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 02:15 - 2014-09-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 02:12 - 2014-09-09 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 02:04 - 2014-09-09 10:04 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Mara\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkdezxe.dll
C:\Users\Mara\AppData\Local\Temp\Quarantine.exe
C:\Users\Mara\AppData\Local\Temp\~7586.exe
C:\Users\Mara\AppData\Local\Temp\~C2A.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 14:32
==================== End Of Log ============================
tady je log.... diky
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Mara (administrator) on MARA-PC on 06-11-2014 19:38:10
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
() C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe
(Dropbox, Inc.) C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Clarus Drive Manager] => C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe [8135744 2013-12-18] (Clarus, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mara\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\MountPoints2: {821a1baa-4260-11e4-87bc-4061860b4475} - E:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
SearchScopes: HKCU - {009E31A3-65AA-49C9-BDF1-297A28EB7A39} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {0BAAC8FB-A908-4FD1-851C-1F205F594A5B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {68A5BFC4-EBDF-40D5-B718-CCD2DA9B9351} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {6B960334-B635-420F-8A58-E72BAA545D30} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {7E0446E9-C847-4829-921A-EAD3FC3DA028} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {88801F01-7AA0-4D76-A8D3-E03DF2ADACCE} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {9001FC15-9197-48FB-82E9-ACB9AA928779} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A85BD942-F40A-4D2E-8EDD-8AE90F46D353} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Noia Fox options - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-11-06]
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: PodoWeb - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi [2014-11-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-06]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Disk Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (PodoWeb) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo [2014-10-21]
CHR Extension: (Skype Click to Call) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-23]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 SZDrvSvc; C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe [18432 2013-12-18] (Clarus, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 mdf16; C:\Program Files\Clarus\Samsung Drive Manager\mdf16.sys [18864 2012-06-21] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl237535bf; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsl237535bf.sys [39464 2014-11-06] (Microsoft Corporation)
R3 mvd23; C:\Program Files\Clarus\Samsung Drive Manager\mvd23.sys [89008 2012-06-21] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-04] (NVIDIA Corporation)
R3 TrdCap; C:\Windows\System32\DRIVERS\TrdCap.sys [1554472 2010-06-09] (Trident Microsystems, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-11-06 19:20 - 2014-11-06 19:22 - 00000000 ____D () C:\AdwCleaner
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Downloads\adwcleaner_3.311.exe
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Desktop\adwcleaner_3.311.exe
2014-11-06 19:17 - 2014-11-06 19:17 - 00001133 _____ () C:\Users\Mara\Desktop\JRT.txt
2014-11-06 19:14 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Desktop\JRT.exe
2014-11-06 19:14 - 2014-11-06 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-11-06 19:13 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Downloads\JRT.exe
2014-11-06 18:41 - 2014-11-06 18:52 - 00021578 _____ () C:\Users\Mara\Desktop\Nmc_2014-11-06_18-41-36.log
2014-11-06 18:40 - 2014-11-06 18:40 - 00000000 ____D () C:\Users\Mara\AppData\Local\Norman Malware Cleaner
2014-11-06 18:27 - 2014-11-06 18:27 - 00006695 _____ () C:\Users\Mara\Desktop\Addition.rar
2014-11-06 18:20 - 2014-11-06 18:25 - 00023146 _____ () C:\Users\Mara\Desktop\Addition.txt
2014-11-06 18:17 - 2014-11-06 19:38 - 00014613 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-11-06 18:17 - 2014-11-06 19:38 - 00000000 ____D () C:\FRST
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Downloads\FRSTLauncher.exe
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Downloads\FRST.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Desktop\FRST.exe
2014-11-06 18:14 - 2014-11-06 18:14 - 00112107 _____ (forum.viry.cz) C:\Users\Mara\Downloads\VerzeOS.exe
2014-11-06 18:09 - 2014-11-06 18:38 - 360763416 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe
2014-11-06 17:47 - 2014-11-06 18:00 - 355092040 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner.exe
2014-11-06 17:43 - 2014-11-06 17:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-06 17:37 - 2014-11-06 17:37 - 00000000 ____D () C:\Users\Mara\Desktop\Původní data aplikace Firefox
2014-11-06 15:41 - 2002-01-01 00:11 - 554374476 _____ () C:\Users\Mara\Downloads\12-let-v-řetězech-CZ-DABING-(2013).avi
2014-11-06 13:05 - 2014-11-06 13:05 - 00000000 ____D () C:\Zaloha
2014-11-06 12:58 - 2014-11-06 18:45 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-06 12:57 - 2014-11-06 12:57 - 04974864 _____ (Piriform Ltd) C:\Users\Mara\Downloads\ccsetup419.exe
2014-11-06 12:57 - 2014-11-06 12:57 - 00384529 _____ () C:\Users\Mara\Downloads\Lista_centrum.exe
2014-11-06 12:56 - 2014-11-06 12:56 - 00733352 _____ () C:\Users\Mara\Downloads\ccleaner-lista-centrumcz.exe
2014-11-04 18:45 - 2014-11-04 18:45 - 00000000 ____D () C:\Users\Mara\AppData\Local\Clarus
2014-10-28 13:22 - 2014-11-06 18:47 - 00000000 ____D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-23 15:16 - 2014-10-23 15:16 - 00000000 ____D () C:\Users\Mara\Desktop\Sygic
2014-10-23 14:18 - 2014-10-23 14:34 - 156473215 _____ () C:\Users\Mara\Downloads\Sygic-13.4.2-(HUD-+-mapy-03.2014-+-navod).rar
2014-10-22 18:36 - 2014-10-22 18:36 - 00000270 __RSH () C:\ProgramData\ntuser.pol
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-10-20 15:20 - 2013-04-05 20:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm.new
2014-10-20 15:19 - 2014-11-06 19:29 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-10-20 15:19 - 2014-10-20 15:21 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Advanced
2014-10-20 15:19 - 2014-10-20 15:19 - 00000000 ____D () C:\Program Files\Shark007
2014-10-20 15:18 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Advanced
2014-10-20 15:18 - 2014-10-20 15:18 - 18037228 _____ () C:\Users\Mara\Downloads\K-Lite_Codec_Pack_Basic.exe
2014-10-20 15:16 - 2014-10-20 15:18 - 51374363 _____ () C:\Users\Mara\Downloads\ADVANCED_Codecs_v473.exe
2014-10-19 18:40 - 2014-10-19 18:40 - 13429504 _____ (Disc Soft Ltd) C:\Users\Mara\Downloads\DTLite4491-0356.exe
2014-10-14 20:13 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 20:13 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 20:13 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 20:12 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 20:12 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 20:12 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 20:12 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 20:12 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 20:12 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 20:12 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 20:12 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 20:12 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 20:12 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 20:12 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 20:12 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 20:12 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 20:12 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 20:12 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 20:12 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 20:12 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 20:12 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 20:12 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 20:12 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 20:12 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 20:12 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 20:12 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 20:12 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 20:12 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 20:12 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 20:12 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 20:12 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 20:09 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 20:09 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 20:09 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-14 20:09 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-14 20:09 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-14 20:09 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-14 20:09 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-14 20:09 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-14 20:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-14 20:09 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-14 20:08 - 2014-08-19 03:40 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 20:08 - 2014-08-19 03:40 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 20:08 - 2014-08-19 02:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-14 20:08 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-14 20:08 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-14 20:08 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-14 20:08 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-14 20:08 - 2014-07-07 02:28 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-14 20:08 - 2014-06-28 01:21 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-14 19:57 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Mara\Desktop\Nová složka
2014-10-14 18:30 - 2014-10-14 18:30 - 02059865 _____ () C:\Users\Mara\Downloads\cpu-z_1.70-en.zip
2014-10-13 14:26 - 2014-10-13 14:28 - 29555583 _____ () C:\Users\Mara\Downloads\Pitbull-Ft.-John-Ryan---Fireball.flac
2014-10-10 18:49 - 2014-10-10 19:05 - 00000000 ____D () C:\Users\Mara\AppData\Local\Microsoft Games
2014-10-09 17:03 - 2014-10-04 16:21 - 00000000 ____D () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW
2014-10-09 17:02 - 1970-01-01 00:59 - 74162521 ____N () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW.rar
2014-10-08 17:20 - 2014-10-08 17:20 - 00000993 _____ () C:\Users\Mara\Desktop\MediaCoder.lnk
2014-10-08 17:20 - 2014-10-08 17:20 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:20 - 00000000 ____D () C:\Program Files\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:19 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Broad Intelligence
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:31 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 19:31 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 19:30 - 2014-09-09 09:19 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 19:30 - 2014-09-08 14:41 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 19:29 - 2014-09-08 14:36 - 02035086 _____ () C:\Windows\WindowsUpdate.log
2014-11-06 19:25 - 2014-09-11 10:05 - 00000000 ___RD () C:\Users\Mara\Dropbox
2014-11-06 19:25 - 2014-09-11 10:01 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Dropbox
2014-11-06 19:24 - 2014-09-22 18:05 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Skype
2014-11-06 19:24 - 2014-09-10 08:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-06 19:24 - 2014-09-09 09:19 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 19:24 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 19:24 - 2002-01-01 00:01 - 00002348 _____ () C:\Windows\PFRO.log
2014-11-06 19:24 - 2002-01-01 00:01 - 00000168 _____ () C:\Windows\setupact.log
2014-11-06 19:16 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-11-06 18:44 - 2014-09-11 17:11 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 17:38 - 2014-09-09 09:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-06 13:03 - 2014-10-04 13:19 - 00000000 ____D () C:\Windows\Minidump
2014-11-06 13:03 - 2014-09-08 15:26 - 00000000 ____D () C:\Windows\Panther
2014-10-30 12:24 - 2014-09-09 09:23 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-24 01:10 - 2014-09-11 15:41 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\vlc
2014-10-21 18:21 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-10-20 15:11 - 2014-09-09 09:48 - 00000000 ____D () C:\Users\Mara\AppData\Local\Windows Live
2014-10-18 20:38 - 2014-09-22 18:05 - 00000000 ____D () C:\ProgramData\Skype
2014-10-15 03:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-15 02:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-15 02:42 - 2009-07-14 05:33 - 00337296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 02:32 - 2014-09-09 10:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 02:15 - 2014-09-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 02:12 - 2014-09-09 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 02:04 - 2014-09-09 10:04 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Mara\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkdezxe.dll
C:\Users\Mara\AppData\Local\Temp\Quarantine.exe
C:\Users\Mara\AppData\Local\Temp\~7586.exe
C:\Users\Mara\AppData\Local\Temp\~C2A.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 14:32
==================== End Of Log ============================
Re: Prosim o kontrolu logu
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 04-11-2014
Ran by Mara at 2014-11-06 19:56:34 Run:1
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF Extension: Noia Fox options - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-11-06]
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: PodoWeb - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi [2014-11-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-06]
CHR Extension: (PodoWeb) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo [2014-10-21]
EmptyTemp:
End
*****************
Processes closed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi => Moved successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi => Moved successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi => Moved successfully.
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully.
C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo => Moved successfully.
EmptyTemp: => Removed 435.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Ran by Mara at 2014-11-06 19:56:34 Run:1
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
FF Extension: Noia Fox options - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi [2014-11-06]
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: PodoWeb - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi [2014-11-06]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-11-06]
CHR Extension: (PodoWeb) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo [2014-10-21]
EmptyTemp:
End
*****************
Processes closed successfully.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
"HKLM\SOFTWARE\Policies\Google" => Key deleted successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\NoiaFoxoption@davidvincent.tld.xpi => Moved successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi => Moved successfully.
C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{a2df9e48-ce26-4812-87d1-df6c5bed5ea9}.xpi => Moved successfully.
C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi => Moved successfully.
C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfjbgbmjaheanejhaompcejgiebnlioo => Moved successfully.
EmptyTemp: => Removed 435.2 MB temporary data.
The system needed a reboot.
==== End of Fixlog ====
Re: Prosim o kontrolu logu
Dekuji reklamy uz sou pryc..
jinak ja budu doma az v Pondeli tak kdyz budes mit cas.. muzes se prosim na to mrknout.. jeste jednou moc dekuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Mara (administrator) on MARA-PC on 06-11-2014 20:26:15
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe
() C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Dropbox, Inc.) C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Clarus Drive Manager] => C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe [8135744 2013-12-18] (Clarus, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mara\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\MountPoints2: {821a1baa-4260-11e4-87bc-4061860b4475} - E:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
SearchScopes: HKCU - {009E31A3-65AA-49C9-BDF1-297A28EB7A39} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {0BAAC8FB-A908-4FD1-851C-1F205F594A5B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {68A5BFC4-EBDF-40D5-B718-CCD2DA9B9351} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {6B960334-B635-420F-8A58-E72BAA545D30} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {7E0446E9-C847-4829-921A-EAD3FC3DA028} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {88801F01-7AA0-4D76-A8D3-E03DF2ADACCE} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {9001FC15-9197-48FB-82E9-ACB9AA928779} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A85BD942-F40A-4D2E-8EDD-8AE90F46D353} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994
FF Homepage: www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: Adblock Plus - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-06]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Disk Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (Skype Click to Call) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-23]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 SZDrvSvc; C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe [18432 2013-12-18] (Clarus, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 mdf16; C:\Program Files\Clarus\Samsung Drive Manager\mdf16.sys [18864 2012-06-21] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl9056eb45; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsl9056eb45.sys [39464 2014-11-06] (Microsoft Corporation)
R3 mvd23; C:\Program Files\Clarus\Samsung Drive Manager\mvd23.sys [89008 2012-06-21] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-04] (NVIDIA Corporation)
R3 TrdCap; C:\Windows\System32\DRIVERS\TrdCap.sys [1554472 2010-06-09] (Trident Microsystems, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-11-06 19:20 - 2014-11-06 19:22 - 00000000 ____D () C:\AdwCleaner
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Downloads\adwcleaner_3.311.exe
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Desktop\adwcleaner_3.311.exe
2014-11-06 19:17 - 2014-11-06 19:17 - 00001133 _____ () C:\Users\Mara\Desktop\JRT.txt
2014-11-06 19:14 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Desktop\JRT.exe
2014-11-06 19:14 - 2014-11-06 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-11-06 19:13 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Downloads\JRT.exe
2014-11-06 18:41 - 2014-11-06 18:52 - 00021578 _____ () C:\Users\Mara\Desktop\Nmc_2014-11-06_18-41-36.log
2014-11-06 18:40 - 2014-11-06 18:40 - 00000000 ____D () C:\Users\Mara\AppData\Local\Norman Malware Cleaner
2014-11-06 18:27 - 2014-11-06 18:27 - 00006695 _____ () C:\Users\Mara\Desktop\Addition.rar
2014-11-06 18:20 - 2014-11-06 18:25 - 00023146 _____ () C:\Users\Mara\Desktop\Addition.txt
2014-11-06 18:17 - 2014-11-06 20:26 - 00014050 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-11-06 18:17 - 2014-11-06 20:26 - 00000000 ____D () C:\FRST
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Downloads\FRSTLauncher.exe
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Downloads\FRST.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Desktop\FRST.exe
2014-11-06 18:14 - 2014-11-06 18:14 - 00112107 _____ (forum.viry.cz) C:\Users\Mara\Downloads\VerzeOS.exe
2014-11-06 18:09 - 2014-11-06 18:38 - 360763416 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe
2014-11-06 17:47 - 2014-11-06 18:00 - 355092040 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner.exe
2014-11-06 17:43 - 2014-11-06 17:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-06 17:37 - 2014-11-06 17:37 - 00000000 ____D () C:\Users\Mara\Desktop\Původní data aplikace Firefox
2014-11-06 15:41 - 2002-01-01 00:11 - 554374476 _____ () C:\Users\Mara\Downloads\12-let-v-řetězech-CZ-DABING-(2013).avi
2014-11-06 13:05 - 2014-11-06 13:05 - 00000000 ____D () C:\Zaloha
2014-11-06 12:58 - 2014-11-06 18:45 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-06 12:57 - 2014-11-06 12:57 - 04974864 _____ (Piriform Ltd) C:\Users\Mara\Downloads\ccsetup419.exe
2014-11-06 12:57 - 2014-11-06 12:57 - 00384529 _____ () C:\Users\Mara\Downloads\Lista_centrum.exe
2014-11-06 12:56 - 2014-11-06 12:56 - 00733352 _____ () C:\Users\Mara\Downloads\ccleaner-lista-centrumcz.exe
2014-11-04 18:45 - 2014-11-04 18:45 - 00000000 ____D () C:\Users\Mara\AppData\Local\Clarus
2014-10-28 13:22 - 2014-11-06 18:47 - 00000000 ____D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-23 15:16 - 2014-10-23 15:16 - 00000000 ____D () C:\Users\Mara\Desktop\Sygic
2014-10-23 14:18 - 2014-10-23 14:34 - 156473215 _____ () C:\Users\Mara\Downloads\Sygic-13.4.2-(HUD-+-mapy-03.2014-+-navod).rar
2014-10-22 18:36 - 2014-11-06 19:59 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-10-20 15:20 - 2013-04-05 20:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm.new
2014-10-20 15:19 - 2014-11-06 20:04 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-10-20 15:19 - 2014-10-20 15:21 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Advanced
2014-10-20 15:19 - 2014-10-20 15:19 - 00000000 ____D () C:\Program Files\Shark007
2014-10-20 15:18 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Advanced
2014-10-20 15:18 - 2014-10-20 15:18 - 18037228 _____ () C:\Users\Mara\Downloads\K-Lite_Codec_Pack_Basic.exe
2014-10-20 15:16 - 2014-10-20 15:18 - 51374363 _____ () C:\Users\Mara\Downloads\ADVANCED_Codecs_v473.exe
2014-10-19 18:40 - 2014-10-19 18:40 - 13429504 _____ (Disc Soft Ltd) C:\Users\Mara\Downloads\DTLite4491-0356.exe
2014-10-14 20:13 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 20:13 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 20:13 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 20:12 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 20:12 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 20:12 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 20:12 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 20:12 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 20:12 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 20:12 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 20:12 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 20:12 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 20:12 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 20:12 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 20:12 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 20:12 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 20:12 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 20:12 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 20:12 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 20:12 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 20:12 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 20:12 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 20:12 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 20:12 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 20:12 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 20:12 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 20:12 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 20:12 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 20:12 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 20:12 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 20:12 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 20:09 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 20:09 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 20:09 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-14 20:09 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-14 20:09 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-14 20:09 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-14 20:09 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-14 20:09 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-14 20:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-14 20:09 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-14 20:08 - 2014-08-19 03:40 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 20:08 - 2014-08-19 03:40 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 20:08 - 2014-08-19 02:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-14 20:08 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-14 20:08 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-14 20:08 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-14 20:08 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-14 20:08 - 2014-07-07 02:28 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-14 20:08 - 2014-06-28 01:21 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-14 19:57 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Mara\Desktop\Nová složka
2014-10-14 18:30 - 2014-10-14 18:30 - 02059865 _____ () C:\Users\Mara\Downloads\cpu-z_1.70-en.zip
2014-10-13 14:26 - 2014-10-13 14:28 - 29555583 _____ () C:\Users\Mara\Downloads\Pitbull-Ft.-John-Ryan---Fireball.flac
2014-10-10 18:49 - 2014-10-10 19:05 - 00000000 ____D () C:\Users\Mara\AppData\Local\Microsoft Games
2014-10-09 17:03 - 2014-10-04 16:21 - 00000000 ____D () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW
2014-10-09 17:02 - 1970-01-01 00:59 - 74162521 ____N () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW.rar
2014-10-08 17:20 - 2014-10-08 17:20 - 00000993 _____ () C:\Users\Mara\Desktop\MediaCoder.lnk
2014-10-08 17:20 - 2014-10-08 17:20 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:20 - 00000000 ____D () C:\Program Files\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:19 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Broad Intelligence
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 20:06 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 20:06 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 20:03 - 2014-09-08 14:41 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 20:02 - 2014-09-08 14:36 - 02042263 _____ () C:\Windows\WindowsUpdate.log
2014-11-06 19:59 - 2014-09-11 10:05 - 00000000 ___RD () C:\Users\Mara\Dropbox
2014-11-06 19:59 - 2014-09-11 10:01 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Dropbox
2014-11-06 19:58 - 2014-09-09 09:19 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 19:58 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 19:58 - 2002-01-01 00:01 - 00000224 _____ () C:\Windows\setupact.log
2014-11-06 19:56 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-11-06 19:44 - 2014-09-11 17:11 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 19:30 - 2014-09-09 09:19 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 19:24 - 2014-09-22 18:05 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Skype
2014-11-06 19:24 - 2014-09-10 08:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-06 19:24 - 2002-01-01 00:01 - 00002348 _____ () C:\Windows\PFRO.log
2014-11-06 19:16 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-11-06 17:38 - 2014-09-09 09:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-06 13:03 - 2014-10-04 13:19 - 00000000 ____D () C:\Windows\Minidump
2014-11-06 13:03 - 2014-09-08 15:26 - 00000000 ____D () C:\Windows\Panther
2014-10-30 12:24 - 2014-09-09 09:23 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-24 01:10 - 2014-09-11 15:41 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\vlc
2014-10-20 15:11 - 2014-09-09 09:48 - 00000000 ____D () C:\Users\Mara\AppData\Local\Windows Live
2014-10-18 20:38 - 2014-09-22 18:05 - 00000000 ____D () C:\ProgramData\Skype
2014-10-15 03:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-15 02:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-15 02:42 - 2009-07-14 05:33 - 00337296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 02:32 - 2014-09-09 10:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 02:15 - 2014-09-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 02:12 - 2014-09-09 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 02:04 - 2014-09-09 10:04 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Mara\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmbaoi_.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 14:32
==================== End Of Log ============================
jinak ja budu doma az v Pondeli tak kdyz budes mit cas.. muzes se prosim na to mrknout.. jeste jednou moc dekuji
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 04-11-2014
Ran by Mara (administrator) on MARA-PC on 06-11-2014 20:26:15
Running from C:\Users\Mara\Desktop
Loaded Profiles: Mara & UpdatusUser (Available profiles: Mara & UpdatusUser)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Čeština (Česká republika)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Clarus, Inc.) C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe
() C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
(Dropbox, Inc.) C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_15_0_0_152.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [Clarus Drive Manager] => C:\Program Files\Clarus\Samsung Drive Manager\Drive Manager.exe [8135744 2013-12-18] (Clarus, Inc.)
HKLM\...\Run: [seznam-listicka-distribuce] => C:\Program Files\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [22065760 2014-10-01] (Skype Technologies S.A.)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Mara\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [cz.seznam.software.szndesktop] => C:\Users\Mara\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [92664 2013-04-12] ()
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4825880 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-1860624291-1627864438-2719766728-1000\...\MountPoints2: {821a1baa-4260-11e4-87bc-4061860b4475} - E:\AutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Drive Manager Real-Time.lnk
ShortcutTarget: Samsung Drive Manager Real-Time.lnk -> C:\Program Files\Clarus\Samsung Drive Manager\ABRTMon.exe (Clarus, Inc.)
Startup: C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Mara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz/?clid=13415
SearchScopes: HKCU - {009E31A3-65AA-49C9-BDF1-297A28EB7A39} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_13415
SearchScopes: HKCU - {0BAAC8FB-A908-4FD1-851C-1F205F594A5B} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
SearchScopes: HKCU - {68A5BFC4-EBDF-40D5-B718-CCD2DA9B9351} URL = http://www.novinky.cz/hledej?w={searchT ... arch_13415
SearchScopes: HKCU - {6B960334-B635-420F-8A58-E72BAA545D30} URL = http://www.mapy.cz/?query={searchTerms} ... arch_13415
SearchScopes: HKCU - {7E0446E9-C847-4829-921A-EAD3FC3DA028} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_13415
SearchScopes: HKCU - {88801F01-7AA0-4D76-A8D3-E03DF2ADACCE} URL = http://encyklopedie.seznam.cz/search?q= ... arch_13415
SearchScopes: HKCU - {9001FC15-9197-48FB-82E9-ACB9AA928779} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_13415
SearchScopes: HKCU - {A85BD942-F40A-4D2E-8EDD-8AE90F46D353} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_13415
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994
FF Homepage: www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Noia Fox - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{7b90e860-5d61-11e0-80e3-0800200c9a66}.xpi [2014-11-06]
FF Extension: Adblock Plus - C:\Users\Mara\AppData\Roaming\Mozilla\Firefox\Profiles\y70dxikc.default-1415291874994\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-06]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/"
CHR Profile: C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-09]
CHR Extension: (Dokumenty Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-09]
CHR Extension: (Disk Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-09]
CHR Extension: (YouTube) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-09]
CHR Extension: (Vyhledávání Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-09]
CHR Extension: (Tabulky Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-09]
CHR Extension: (Skype Click to Call) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-23]
CHR Extension: (Peněženka Google) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-09]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2014-10-20]
CHR Extension: (Gmail) - C:\Users\Mara\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-09]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 c2cautoupdatesvc; C:\Program Files\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 SZDrvSvc; C:\Program Files\Clarus\Samsung Drive Manager\SZDrvSvc.exe [18432 2013-12-18] (Clarus, Inc.) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 mdf16; C:\Program Files\Clarus\Samsung Drive Manager\mdf16.sys [18864 2012-06-21] ()
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 MpKsl9056eb45; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D7BE899A-A3B8-4663-A0E3-194E72575708}\MpKsl9056eb45.sys [39464 2014-11-06] (Microsoft Corporation)
R3 mvd23; C:\Program Files\Clarus\Samsung Drive Manager\mvd23.sys [89008 2012-06-21] ()
R0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-06-04] (NVIDIA Corporation)
R3 TrdCap; C:\Windows\System32\DRIVERS\TrdCap.sys [1554472 2010-06-09] (Trident Microsystems, Inc.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 19:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-11-06 19:20 - 2014-11-06 19:22 - 00000000 ____D () C:\AdwCleaner
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Downloads\adwcleaner_3.311.exe
2014-11-06 19:19 - 2014-11-06 19:19 - 01375089 _____ () C:\Users\Mara\Desktop\adwcleaner_3.311.exe
2014-11-06 19:17 - 2014-11-06 19:17 - 00001133 _____ () C:\Users\Mara\Desktop\JRT.txt
2014-11-06 19:14 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Desktop\JRT.exe
2014-11-06 19:14 - 2014-11-06 19:14 - 00000000 ____D () C:\Windows\ERUNT
2014-11-06 19:13 - 2014-11-06 19:14 - 01706939 _____ (Thisisu) C:\Users\Mara\Downloads\JRT.exe
2014-11-06 18:41 - 2014-11-06 18:52 - 00021578 _____ () C:\Users\Mara\Desktop\Nmc_2014-11-06_18-41-36.log
2014-11-06 18:40 - 2014-11-06 18:40 - 00000000 ____D () C:\Users\Mara\AppData\Local\Norman Malware Cleaner
2014-11-06 18:27 - 2014-11-06 18:27 - 00006695 _____ () C:\Users\Mara\Desktop\Addition.rar
2014-11-06 18:20 - 2014-11-06 18:25 - 00023146 _____ () C:\Users\Mara\Desktop\Addition.txt
2014-11-06 18:17 - 2014-11-06 20:26 - 00014050 _____ () C:\Users\Mara\Desktop\FRST.txt
2014-11-06 18:17 - 2014-11-06 20:26 - 00000000 ____D () C:\FRST
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Downloads\FRSTLauncher.exe
2014-11-06 18:16 - 2014-11-06 18:16 - 00112640 _____ (forum.viry.cz) C:\Users\Mara\Desktop\FRSTLauncher.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Downloads\FRST.exe
2014-11-06 18:15 - 2014-11-06 18:15 - 01106432 _____ (Farbar) C:\Users\Mara\Desktop\FRST.exe
2014-11-06 18:14 - 2014-11-06 18:14 - 00112107 _____ (forum.viry.cz) C:\Users\Mara\Downloads\VerzeOS.exe
2014-11-06 18:09 - 2014-11-06 18:38 - 360763416 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner(1).exe
2014-11-06 17:47 - 2014-11-06 18:00 - 355092040 _____ (Norman Shark AS) C:\Users\Mara\Downloads\Norman_Malware_Cleaner.exe
2014-11-06 17:43 - 2014-11-06 17:43 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-06 17:37 - 2014-11-06 17:37 - 00000000 ____D () C:\Users\Mara\Desktop\Původní data aplikace Firefox
2014-11-06 15:41 - 2002-01-01 00:11 - 554374476 _____ () C:\Users\Mara\Downloads\12-let-v-řetězech-CZ-DABING-(2013).avi
2014-11-06 13:05 - 2014-11-06 13:05 - 00000000 ____D () C:\Zaloha
2014-11-06 12:58 - 2014-11-06 18:45 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-06 12:58 - 2014-11-06 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-06 12:57 - 2014-11-06 12:57 - 04974864 _____ (Piriform Ltd) C:\Users\Mara\Downloads\ccsetup419.exe
2014-11-06 12:57 - 2014-11-06 12:57 - 00384529 _____ () C:\Users\Mara\Downloads\Lista_centrum.exe
2014-11-06 12:56 - 2014-11-06 12:56 - 00733352 _____ () C:\Users\Mara\Downloads\ccleaner-lista-centrumcz.exe
2014-11-04 18:45 - 2014-11-04 18:45 - 00000000 ____D () C:\Users\Mara\AppData\Local\Clarus
2014-10-28 13:22 - 2014-11-06 18:47 - 00000000 ____D () C:\ProgramData\01e58235-010d-43b1-8340-277d43a75321
2014-10-23 15:16 - 2014-10-23 15:16 - 00000000 ____D () C:\Users\Mara\Desktop\Sygic
2014-10-23 14:18 - 2014-10-23 14:34 - 156473215 _____ () C:\Users\Mara\Downloads\Sygic-13.4.2-(HUD-+-mapy-03.2014-+-navod).rar
2014-10-22 18:36 - 2014-11-06 19:59 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2014-10-20 15:21 - 2014-10-20 15:21 - 00000000 ____D () C:\Program Files\K-Lite Codec Pack
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
2014-10-20 15:20 - 2014-10-20 15:20 - 00000000 ____D () C:\Program Files\Seznam.cz
2014-10-20 15:20 - 2013-04-05 20:26 - 01679360 _____ () C:\Windows\system32\ac3filter.acm.new
2014-10-20 15:19 - 2014-11-06 20:04 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Seznam.cz
2014-10-20 15:19 - 2014-10-20 15:21 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Advanced
2014-10-20 15:19 - 2014-10-20 15:19 - 00000000 ____D () C:\Program Files\Shark007
2014-10-20 15:18 - 2014-10-20 15:21 - 00000000 ____D () C:\ProgramData\Advanced
2014-10-20 15:18 - 2014-10-20 15:18 - 18037228 _____ () C:\Users\Mara\Downloads\K-Lite_Codec_Pack_Basic.exe
2014-10-20 15:16 - 2014-10-20 15:18 - 51374363 _____ () C:\Users\Mara\Downloads\ADVANCED_Codecs_v473.exe
2014-10-19 18:40 - 2014-10-19 18:40 - 13429504 _____ (Disc Soft Ltd) C:\Users\Mara\Downloads\DTLite4491-0356.exe
2014-10-14 20:13 - 2014-10-10 02:44 - 00396288 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-14 20:13 - 2014-10-10 02:44 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-14 20:13 - 2014-10-10 02:39 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-14 20:12 - 2014-10-07 03:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-14 20:12 - 2014-09-29 01:41 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-14 20:12 - 2014-09-25 23:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-14 20:12 - 2014-09-25 23:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-14 20:12 - 2014-09-25 23:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-14 20:12 - 2014-09-25 23:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-14 20:12 - 2014-09-19 02:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-14 20:12 - 2014-09-19 02:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-14 20:12 - 2014-09-19 02:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-14 20:12 - 2014-09-19 02:14 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-14 20:12 - 2014-09-19 02:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-14 20:12 - 2014-09-19 02:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-14 20:12 - 2014-09-19 01:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-14 20:12 - 2014-09-19 01:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-14 20:12 - 2014-09-19 01:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-14 20:12 - 2014-09-19 01:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-14 20:12 - 2014-09-19 01:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-14 20:12 - 2014-09-19 01:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-14 20:12 - 2014-09-19 01:50 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-14 20:12 - 2014-09-19 01:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-14 20:12 - 2014-09-19 01:44 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-14 20:12 - 2014-09-19 01:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-14 20:12 - 2014-09-19 01:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-14 20:12 - 2014-09-19 01:20 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-14 20:12 - 2014-09-19 01:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-14 20:12 - 2014-09-19 01:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-14 20:12 - 2014-09-19 00:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-14 20:12 - 2014-09-19 00:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-14 20:12 - 2014-09-19 00:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-14 20:12 - 2014-09-04 06:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-14 20:09 - 2014-09-18 02:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-14 20:09 - 2014-09-13 02:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-14 20:09 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-14 20:09 - 2014-08-29 02:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-10-14 20:09 - 2014-07-17 02:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-14 20:09 - 2014-07-17 02:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-14 20:09 - 2014-07-17 02:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-14 20:09 - 2014-07-17 02:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-14 20:09 - 2014-07-17 02:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-10-14 20:09 - 2014-07-09 02:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-10-14 20:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-10-14 20:09 - 2014-06-18 23:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-14 20:09 - 2014-06-18 23:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-14 20:08 - 2014-08-19 03:41 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-14 20:08 - 2014-08-19 03:40 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-14 20:08 - 2014-08-19 03:40 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-14 20:08 - 2014-08-19 02:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-14 20:08 - 2014-07-07 02:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-14 20:08 - 2014-07-07 02:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-14 20:08 - 2014-07-07 02:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-14 20:08 - 2014-07-07 02:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-14 20:08 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-14 20:08 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-14 20:08 - 2014-07-07 02:28 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-14 20:08 - 2014-06-28 01:21 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-14 20:08 - 2014-06-28 01:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-14 19:57 - 2014-10-14 19:57 - 00000000 ____D () C:\Users\Mara\Desktop\Nová složka
2014-10-14 18:30 - 2014-10-14 18:30 - 02059865 _____ () C:\Users\Mara\Downloads\cpu-z_1.70-en.zip
2014-10-13 14:26 - 2014-10-13 14:28 - 29555583 _____ () C:\Users\Mara\Downloads\Pitbull-Ft.-John-Ryan---Fireball.flac
2014-10-10 18:49 - 2014-10-10 19:05 - 00000000 ____D () C:\Users\Mara\AppData\Local\Microsoft Games
2014-10-09 17:03 - 2014-10-04 16:21 - 00000000 ____D () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW
2014-10-09 17:02 - 1970-01-01 00:59 - 74162521 ____N () C:\Users\Mara\Desktop\Verona-Meziprostor-WEB-2014-I_KnoW.rar
2014-10-08 17:20 - 2014-10-08 17:20 - 00000993 _____ () C:\Users\Mara\Desktop\MediaCoder.lnk
2014-10-08 17:20 - 2014-10-08 17:20 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:20 - 00000000 ____D () C:\Program Files\MediaCoder
2014-10-08 17:19 - 2014-10-08 17:19 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Broad Intelligence
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-06 20:06 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-06 20:06 - 2009-07-14 05:34 - 00023152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-06 20:03 - 2014-09-08 14:41 - 01582262 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-06 20:02 - 2014-09-08 14:36 - 02042263 _____ () C:\Windows\WindowsUpdate.log
2014-11-06 19:59 - 2014-09-11 10:05 - 00000000 ___RD () C:\Users\Mara\Dropbox
2014-11-06 19:59 - 2014-09-11 10:01 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Dropbox
2014-11-06 19:58 - 2014-09-09 09:19 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-06 19:58 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-06 19:58 - 2002-01-01 00:01 - 00000224 _____ () C:\Windows\setupact.log
2014-11-06 19:56 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-11-06 19:44 - 2014-09-11 17:11 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-06 19:30 - 2014-09-09 09:19 - 00000940 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-06 19:24 - 2014-09-22 18:05 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\Skype
2014-11-06 19:24 - 2014-09-10 08:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-06 19:24 - 2002-01-01 00:01 - 00002348 _____ () C:\Windows\PFRO.log
2014-11-06 19:16 - 2009-07-14 03:04 - 00000580 _____ () C:\Windows\win.ini
2014-11-06 17:38 - 2014-09-09 09:24 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-11-06 13:03 - 2014-10-04 13:19 - 00000000 ____D () C:\Windows\Minidump
2014-11-06 13:03 - 2014-09-08 15:26 - 00000000 ____D () C:\Windows\Panther
2014-10-30 12:24 - 2014-09-09 09:23 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-10-24 01:10 - 2014-09-11 15:41 - 00000000 ____D () C:\Users\Mara\AppData\Roaming\vlc
2014-10-20 15:11 - 2014-09-09 09:48 - 00000000 ____D () C:\Users\Mara\AppData\Local\Windows Live
2014-10-18 20:38 - 2014-09-22 18:05 - 00000000 ____D () C:\ProgramData\Skype
2014-10-15 03:22 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-10-15 02:55 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-10-15 02:42 - 2009-07-14 05:33 - 00337296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-15 02:32 - 2014-09-09 10:05 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-15 02:15 - 2014-09-09 14:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-15 02:12 - 2014-09-09 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-15 02:04 - 2014-09-09 10:04 - 100290944 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Mara\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmbaoi_.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-05 14:32
==================== End Of Log ============================
Re: Prosim o kontrolu logu
Děkuji;) 

Přispějete na provoz fóra?