dvojity ´´ ˇˇ
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Vážení uživaterlé!
Ve dnech 4. - 6-9.2026 budou někteříí naši členové na každoročním srazu fóra. Žádáme vás, abyste měli strpení, nemusí se na na řešení vašeho problému dostat hned. Děkujeme za pochopení.
dvojity ´´ ˇˇ
zdravim, mam zrejme proble s keyloggerom, teda aspon co som sa docital. mohol by som vas poprosit o kontrolu? dakujem
Logfile of random's system information tool 1.10 (written by random/random)
Run by f4r0 at 2015-01-09 14:13:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 48 GB (48%) free of 101 GB
Total RAM: 8190 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:13:22, on 9. 1. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HTPC\htpcons.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\f4r0.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [htpcons] C:\Program Files (x86)\HTPC\htpcons.exe /STARTUP
O4 - HKCU\..\Run: [uTorrent] "C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [AshSnap] C:\Program Files (x86)\Ashampoo\Ashampoo Snap 7\ashsnap.exe
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1420801530
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BitRaider Mini-Support Service Stub Loader (BRSptStub) - BitRaider, LLC - C:\ProgramData\BitRaider\BRSptStub.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Installer Service - Unknown owner - C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9970 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" /rep_new
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
"C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\HTPC\htpcons.exe" /STARTUP
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe" "C:\Users\f4r0\AppData\Local\Plex Media Server\Plug-ins\Framework.bundle\Contents\Resources\Versions\2\Python/bootstrap.py" "C:\Users\f4r0\AppData\Local\Plex Media Server\Plug-ins\System.bundle"
\??\C:\Windows\system32\conhost.exe "1018181220-13369284411604084436-225354109-1514608377957006565-2036698332-398583545
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3756.0.1284970965\533977559" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x6899 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.2.1003115486\1741662260" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.3.1129274373\1911423875" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.4.1108102683\246940193" /prefetch:673131151
"C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.40.2143542031\1857838952" /prefetch:673131151
"C:\Users\f4r0\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-11-12 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-11-12 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2014-05-30 383992]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-10-01 5595336]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe [2014-11-26 1385808]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2014-12-15 3618648]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-02-14 1564992]
"Plex Media Server"=C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [2014-12-21 5142664]
"AshSnap"=C:\Program Files (x86)\Ashampoo\Ashampoo Snap 7\ashsnap.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Adobe Speed Launcher"=1420801530 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-10-15 157480]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-20 767176]
"htpcons"=C:\Program Files (x86)\HTPC\htpcons.exe [2014-12-04 2983424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"AutoHideIPunstall"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-01-09 14:13:21 ----D---- C:\rsit
2015-01-09 13:57:49 ----D---- C:\Program Files\trend micro
2015-01-09 11:57:32 ----ASH---- C:\hiberfil.sys
2015-01-09 11:47:55 ----A---- C:\Windows\SYSWOW64\sh4native.exe
2015-01-09 11:11:52 ----D---- C:\ProgramData\ESET
2015-01-09 11:11:52 ----D---- C:\Program Files\ESET
2015-01-07 21:54:04 ----D---- C:\ProgramData\htpc
2015-01-07 21:53:41 ----A---- C:\Windows\system32\parent.lnk
2015-01-07 21:53:40 ----D---- C:\Program Files (x86)\HTPC
2015-01-07 17:00:05 ----D---- C:\Users\f4r0\AppData\Roaming\avidemux
2015-01-07 16:59:55 ----D---- C:\Program Files\Avidemux 2.6 - 64bits
2015-01-07 16:37:25 ----D---- C:\ProgramData\BitRaider
2015-01-05 18:30:47 ----D---- C:\Windows\SYSWOW64\GPBAK
2015-01-05 18:30:47 ----A---- C:\Windows\SYSWOW64\gpedit.msc
2015-01-05 18:30:47 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2015-01-05 14:33:51 ----D---- C:\Users\f4r0\AppData\Roaming\AutoHideIP
2015-01-05 14:33:51 ----D---- C:\ProgramData\AutoHideIP
2015-01-05 11:17:11 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-01-04 21:56:32 ----D---- C:\Fraps
2014-12-28 15:48:52 ----D---- C:\Users\f4r0\AppData\Roaming\Frontier Developments
2014-12-27 12:35:07 ----A---- C:\Windows\system32\DfSdkBt.exe
2014-12-27 12:26:23 ----D---- C:\Program Files (x86)\Ashampoo
2014-12-26 22:06:08 ----D---- C:\Users\f4r0\AppData\Roaming\LG Electronics
2014-12-25 13:20:21 ----D---- C:\Program Files (x86)\Plex
2014-12-18 11:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-12-18 11:24:37 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-17 10:00:21 ----SHD---- C:\found.000
2014-12-16 21:00:00 ----D---- C:\Windows\Acronis
2014-12-16 20:56:25 ----D---- C:\ProgramData\Acronis
2014-12-16 20:55:19 ----A---- C:\Windows\system32\drivers\snapman.sys
2014-12-16 20:55:18 ----A---- C:\Windows\system32\drivers\fltsrv.sys
2014-12-16 20:55:09 ----D---- C:\Program Files (x86)\Acronis
2014-12-15 18:19:59 ----D---- C:\Users\f4r0\AppData\Roaming\mIRC
2014-12-15 17:44:07 ----D---- C:\Users\f4r0\AppData\Roaming\Miranda
2014-12-15 17:43:30 ----D---- C:\Program Files (x86)\Miranda IM
2014-12-15 16:49:20 ----D---- C:\Windows\SYSWOW64\Wat
2014-12-15 16:49:20 ----D---- C:\Windows\system32\Wat
2014-12-14 15:30:43 ----A---- C:\autoexec.bat
2014-12-14 15:30:15 ----D---- C:\Program Files (x86)\Enigma Software Group
2014-12-14 15:22:59 ----D---- C:\ProgramData\Malwarebytes
2014-12-14 14:40:13 ----D---- C:\Windows\ERUNT
2014-12-13 12:46:42 ----D---- C:\Users\f4r0\AppData\Roaming\AMD
2014-12-12 20:23:40 ----D---- C:\Users\f4r0\AppData\Roaming\11bitstudios
2014-12-12 20:21:27 ----D---- C:\Program Files\7-Zip
2014-12-10 18:08:01 ----D---- C:\Windows\system32\appraiser
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mfps.dll
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mferror.dll
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-12-10 17:06:33 ----A---- C:\Windows\system32\rrinstaller.exe
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mfps.dll
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mfpmp.exe
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mferror.dll
2014-12-10 17:06:32 ----A---- C:\Windows\system32\mf.dll
2014-12-10 13:52:18 ----D---- C:\Users\f4r0\AppData\Roaming\Promotion Software GmbH
2014-12-10 10:30:24 ----A---- C:\Windows\system32\appraiser.dll
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aitstatic.exe
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aepic.dll
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aeinv.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\invagent.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\generaltel.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\devinv.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\aepdu.dll
2014-12-10 10:30:11 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 10:30:11 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-12-10 10:30:10 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\iernonce.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ie4uinit.exe
2014-12-10 10:30:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-12-10 10:30:07 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\urlmon.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\iedkcs32.dll
2014-12-10 10:30:05 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-12-10 10:30:05 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\msfeeds.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\iesetup.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\dxtrans.dll
2014-12-10 10:30:03 ----A---- C:\Windows\system32\iertutil.dll
2014-12-10 10:30:03 ----A---- C:\Windows\system32\ieapfltr.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-12-10 10:30:01 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-12-10 10:30:01 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-12-10 10:30:01 ----A---- C:\Windows\system32\jsproxy.dll
2014-12-10 10:30:01 ----A---- C:\Windows\system32\dxtmsft.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\mshtmled.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\jscript9diag.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\jscript9.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\ieui.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\ieframe.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\wininet.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\vbscript.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\msrating.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-12-10 10:29:58 ----A---- C:\Windows\system32\mshtml.dll
2014-12-10 10:28:28 ----A---- C:\Windows\SYSWOW64\charmap.exe
2014-12-10 10:28:28 ----A---- C:\Windows\system32\charmap.exe
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmWmiPl.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmSvc.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmAuto.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 10:28:25 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-12-10 10:28:25 ----A---- C:\Windows\system32\tzres.dll
2014-12-10 02:29:24 ----D---- C:\ProgramData\ATI
2014-12-10 02:14:58 ----D---- C:\Program Files (x86)\AMD AVT
2014-12-10 02:12:06 ----D---- C:\Program Files (x86)\AMD
======List of files/folders modified in the last 1 month======
2015-01-09 14:13:22 ----D---- C:\Windows\Temp
2015-01-09 14:13:12 ----D---- C:\Users\f4r0\AppData\Roaming\uTorrent
2015-01-09 13:57:49 ----RD---- C:\Program Files
2015-01-09 12:21:50 ----D---- C:\Windows\system32\config
2015-01-09 12:08:46 ----RD---- C:\Program Files (x86)
2015-01-09 12:08:26 ----D---- C:\Windows
2015-01-09 12:06:08 ----D---- C:\ProgramData\Origin
2015-01-09 12:05:39 ----D---- C:\Program Files (x86)\Origin
2015-01-09 11:47:55 ----D---- C:\Windows\SysWOW64
2015-01-09 11:12:46 ----SHD---- C:\Windows\Installer
2015-01-09 11:12:26 ----D---- C:\Windows\system32\DriverStore
2015-01-09 11:12:26 ----D---- C:\Windows\system32\drivers
2015-01-09 11:12:26 ----D---- C:\Windows\system32\catroot
2015-01-09 11:12:26 ----D---- C:\Windows\inf
2015-01-09 11:11:52 ----HD---- C:\ProgramData
2015-01-09 11:02:53 ----D---- C:\Windows\Prefetch
2015-01-08 16:51:02 ----D---- C:\Windows\system32\Tasks
2015-01-08 16:51:01 ----D---- C:\Windows\Tasks
2015-01-08 16:51:01 ----D---- C:\Windows\AutoKMS
2015-01-08 16:51:00 ----D---- C:\Program Files\Common Files\System
2015-01-07 21:53:41 ----D---- C:\Windows\System32
2015-01-07 16:25:49 ----D---- C:\Program Files (x86)\Common Files
2015-01-06 04:36:02 ----N---- C:\Windows\system32\MpSigStub.exe
2015-01-05 18:30:47 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2015-01-05 13:39:40 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2015-01-05 12:08:59 ----SD---- C:\Users\f4r0\AppData\Roaming\Microsoft
2015-01-04 11:36:04 ----D---- C:\Windows\SoftwareDistribution
2015-01-04 11:33:03 ----D---- C:\Users\f4r0\AppData\Roaming\DAEMON Tools Lite
2015-01-04 11:33:03 ----D---- C:\Program Files (x86)\Steam
2015-01-04 11:33:02 ----D---- C:\Windows\Logs
2015-01-03 19:22:01 ----D---- C:\Windows\SYSWOW64\directx
2015-01-03 15:16:16 ----D---- C:\Windows\winsxs
2015-01-03 15:06:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-12-30 21:53:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-29 11:58:51 ----D---- C:\Windows\system32\NDF
2014-12-29 11:57:46 ----SD---- C:\ProgramData\Microsoft
2014-12-27 12:52:38 ----D---- C:\Windows\Panther
2014-12-27 12:35:10 ----D---- C:\ProgramData\Ashampoo
2014-12-27 12:27:09 ----D---- C:\Users\f4r0\AppData\Roaming\Ashampoo
2014-12-26 22:03:48 ----D---- C:\Program Files (x86)\LG Electronics
2014-12-26 19:39:08 ----D---- C:\Users\f4r0\AppData\Roaming\.minecraft
2014-12-25 13:21:07 ----D---- C:\Users\f4r0\AppData\Roaming\Apple Computer
2014-12-25 13:20:13 ----D---- C:\ProgramData\Package Cache
2014-12-24 17:59:31 ----D---- C:\Windows\system32\catroot2
2014-12-23 15:17:59 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2014-12-19 22:27:23 ----D---- C:\Windows\Minidump
2014-12-19 10:21:52 ----D---- C:\Windows\system32\LogFiles
2014-12-18 12:00:44 ----D---- C:\Users\f4r0\AppData\Roaming\SpaceEngineers
2014-12-15 19:28:53 ----D---- C:\Program Files (x86)\epson
2014-12-15 18:33:54 ----D---- C:\ProgramData\EPSON
2014-12-15 18:33:21 ----D---- C:\Windows\twain_32
2014-12-15 17:05:54 ----D---- C:\Windows\system32\drivers\etc
2014-12-14 16:54:04 ----D---- C:\Windows\Cursors
2014-12-13 20:01:24 ----DC---- C:\Windows\system32\DRVSTORE
2014-12-13 20:01:05 ----D---- C:\Program Files\MKVToolNix
2014-12-13 15:11:01 ----D---- C:\Windows\rescache
2014-12-12 22:17:40 ----D---- C:\Windows\SYSWOW64\sk-SK
2014-12-12 22:17:40 ----D---- C:\Windows\system32\sk-SK
2014-12-11 11:56:07 ----D---- C:\Windows\debug
2014-12-10 18:08:01 ----SD---- C:\Windows\system32\CompatTel
2014-12-10 18:08:01 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-10 18:08:01 ----D---- C:\Windows\system32\en-US
2014-12-10 18:08:01 ----D---- C:\Windows\PolicyDefinitions
2014-12-10 18:08:01 ----D---- C:\Windows\AppCompat
2014-12-10 18:08:01 ----D---- C:\Program Files\Internet Explorer
2014-12-10 18:08:00 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-10 17:11:45 ----D---- C:\Windows\system32\MRT
2014-12-10 17:08:54 ----A---- C:\Windows\system32\MRT.exe
2014-12-10 17:08:49 ----D---- C:\ProgramData\Microsoft Help
2014-12-10 16:26:27 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-12-10 02:33:29 ----D---- C:\Windows\Microsoft.NET
2014-12-10 02:14:59 ----D---- C:\ProgramData\AMD
2014-12-10 02:14:27 ----D---- C:\Program Files\AMD
2014-12-10 02:13:24 ----D---- C:\Program Files\ATI Technologies
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2014-10-10 63160]
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2014-12-16 118560]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2014-12-16 276256]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-30 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2014-10-10 243440]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2014-10-10 169280]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2014-10-10 44632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2014-10-10 222280]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys []
S3 andnetadb;ADB Interface DriverNet; C:\Windows\System32\Drivers\lgandnetadb.sys [2014-05-27 31744]
S3 AndnetBus;LGE Mobile USB Composite Device; C:\Windows\system32\DRIVERS\lgandnetbus64.sys [2014-05-27 20992]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [2014-07-07 29184]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [2014-07-07 36352]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2012-08-30 1930240]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [2015-01-07 78088]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-23 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [2014-01-07 14872]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2012-06-05 237968]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 206080]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbrndis6;USB RNDIS6 Adapter; C:\Windows\system32\DRIVERS\usb80236.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-13 73984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-10-01 1349576]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-12-03 76152]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10 267440]
S3 BRSptStub;BitRaider Mini-Support Service Stub Loader; C:\ProgramData\BitRaider\BRSptStub.exe [2015-01-07 363208]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Installer Service;Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe [2014-09-03 125288]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1903472]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-12-15 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by f4r0 at 2015-01-09 14:13:21
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 48 GB (48%) free of 101 GB
Total RAM: 8190 MB (71% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:13:22, on 9. 1. 2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17496)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Samsung\Kies\Kies.exe
C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\HTPC\htpcons.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\f4r0.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [htpcons] C:\Program Files (x86)\HTPC\htpcons.exe /STARTUP
O4 - HKCU\..\Run: [uTorrent] "C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKCU\..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
O4 - HKCU\..\Run: [Plex Media Server] "C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
O4 - HKCU\..\Run: [AshSnap] C:\Program Files (x86)\Ashampoo\Ashampoo Snap 7\ashsnap.exe
O4 - HKCU\..\RunOnce: [Adobe Speed Launcher] 1420801530
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BitRaider Mini-Support Service Stub Loader (BRSptStub) - BitRaider, LLC - C:\ProgramData\BitRaider\BRSptStub.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Installer Service - Unknown owner - C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9970 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
"taskhost.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" /rep_new
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
C:\Windows\System32\alg.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
"C:\Program Files (x86)\Samsung\Kies\Kies.exe" /preload
"C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
"C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\HTPC\htpcons.exe" /STARTUP
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe" "C:\Users\f4r0\AppData\Local\Plex Media Server\Plug-ins\Framework.bundle\Contents\Resources\Versions\2\Python/bootstrap.py" "C:\Users\f4r0\AppData\Local\Plex Media Server\Plug-ins\System.bundle"
\??\C:\Windows\system32\conhost.exe "1018181220-13369284411604084436-225354109-1514608377957006565-2036698332-398583545
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe"
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="3756.0.1284970965\533977559" --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,17,38 --gpu-vendor-id=0x1002 --gpu-device-id=0x6899 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=14.501.1003.0 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.2.1003115486\1741662260" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.3.1129274373\1911423875" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.4.1108102683\246940193" /prefetch:673131151
"C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-deferred-image-decoding --lang=sk --force-fieldtrials="BrowserBlacklist/Enabled/ChromeSuggestions/Default/DomRel-Enable/enable/EmbeddedSearch/Group4 pct:10d stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/EnhancedBookmarks/Default/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GCM/Enabled/NewProfileManagement/OldAvatarMenu/OmniboxBundledExperimentV1/StandardR4/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/QUIC/Enabled/RememberCertificateErrorDecisions/Default/SPDY/DefaultSpdy31Enabled/SRTPromptFieldTrial/Default/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Experiment/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_94/UMA-Uniformity-Trial-10-Percent/group_07/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_01/UMA-Uniformity-Trial-5-Percent/group_01/UMA-Uniformity-Trial-50-Percent/default/VoiceTrigger/Install/" --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --channel="3756.40.2143542031\1857838952" /prefetch:673131151
"C:\Users\f4r0\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-11-12 462760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-11-12 171944]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2012-11-05 108144]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2014-05-30 383992]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2014-10-01 5595336]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"=C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe [2014-11-26 1385808]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"EADM"=C:\Program Files (x86)\Origin\Origin.exe [2014-12-15 3618648]
"KiesPreload"=C:\Program Files (x86)\Samsung\Kies\Kies.exe [2014-02-14 1564992]
"Plex Media Server"=C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [2014-12-21 5142664]
"AshSnap"=C:\Program Files (x86)\Ashampoo\Ashampoo Snap 7\ashsnap.exe []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Adobe Speed Launcher"=1420801530 []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"KiesTrayAgent"=C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [2014-02-14 311616]
"Adobe ARM"=C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-11-20 1021128]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-09-26 271744]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2014-10-15 157480]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2014-11-20 767176]
"htpcons"=C:\Program Files (x86)\HTPC\htpcons.exe [2014-12-04 2983424]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\RunOnce]
"AutoHideIPunstall"= []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2015-01-09 14:13:21 ----D---- C:\rsit
2015-01-09 13:57:49 ----D---- C:\Program Files\trend micro
2015-01-09 11:57:32 ----ASH---- C:\hiberfil.sys
2015-01-09 11:47:55 ----A---- C:\Windows\SYSWOW64\sh4native.exe
2015-01-09 11:11:52 ----D---- C:\ProgramData\ESET
2015-01-09 11:11:52 ----D---- C:\Program Files\ESET
2015-01-07 21:54:04 ----D---- C:\ProgramData\htpc
2015-01-07 21:53:41 ----A---- C:\Windows\system32\parent.lnk
2015-01-07 21:53:40 ----D---- C:\Program Files (x86)\HTPC
2015-01-07 17:00:05 ----D---- C:\Users\f4r0\AppData\Roaming\avidemux
2015-01-07 16:59:55 ----D---- C:\Program Files\Avidemux 2.6 - 64bits
2015-01-07 16:37:25 ----D---- C:\ProgramData\BitRaider
2015-01-05 18:30:47 ----D---- C:\Windows\SYSWOW64\GPBAK
2015-01-05 18:30:47 ----A---- C:\Windows\SYSWOW64\gpedit.msc
2015-01-05 18:30:47 ----A---- C:\Windows\SYSWOW64\appmgr.dll
2015-01-05 14:33:51 ----D---- C:\Users\f4r0\AppData\Roaming\AutoHideIP
2015-01-05 14:33:51 ----D---- C:\ProgramData\AutoHideIP
2015-01-05 11:17:11 ----A---- C:\Windows\system32\FNTCACHE.DAT
2015-01-04 21:56:32 ----D---- C:\Fraps
2014-12-28 15:48:52 ----D---- C:\Users\f4r0\AppData\Roaming\Frontier Developments
2014-12-27 12:35:07 ----A---- C:\Windows\system32\DfSdkBt.exe
2014-12-27 12:26:23 ----D---- C:\Program Files (x86)\Ashampoo
2014-12-26 22:06:08 ----D---- C:\Users\f4r0\AppData\Roaming\LG Electronics
2014-12-25 13:20:21 ----D---- C:\Program Files (x86)\Plex
2014-12-18 11:24:38 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-12-18 11:24:37 ----A---- C:\Windows\system32\ieUnatt.exe
2014-12-17 10:00:21 ----SHD---- C:\found.000
2014-12-16 21:00:00 ----D---- C:\Windows\Acronis
2014-12-16 20:56:25 ----D---- C:\ProgramData\Acronis
2014-12-16 20:55:19 ----A---- C:\Windows\system32\drivers\snapman.sys
2014-12-16 20:55:18 ----A---- C:\Windows\system32\drivers\fltsrv.sys
2014-12-16 20:55:09 ----D---- C:\Program Files (x86)\Acronis
2014-12-15 18:19:59 ----D---- C:\Users\f4r0\AppData\Roaming\mIRC
2014-12-15 17:44:07 ----D---- C:\Users\f4r0\AppData\Roaming\Miranda
2014-12-15 17:43:30 ----D---- C:\Program Files (x86)\Miranda IM
2014-12-15 16:49:20 ----D---- C:\Windows\SYSWOW64\Wat
2014-12-15 16:49:20 ----D---- C:\Windows\system32\Wat
2014-12-14 15:30:43 ----A---- C:\autoexec.bat
2014-12-14 15:30:15 ----D---- C:\Program Files (x86)\Enigma Software Group
2014-12-14 15:22:59 ----D---- C:\ProgramData\Malwarebytes
2014-12-14 14:40:13 ----D---- C:\Windows\ERUNT
2014-12-13 12:46:42 ----D---- C:\Users\f4r0\AppData\Roaming\AMD
2014-12-12 20:23:40 ----D---- C:\Users\f4r0\AppData\Roaming\11bitstudios
2014-12-12 20:21:27 ----D---- C:\Program Files\7-Zip
2014-12-10 18:08:01 ----D---- C:\Windows\system32\appraiser
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mfps.dll
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mferror.dll
2014-12-10 17:06:33 ----A---- C:\Windows\SYSWOW64\mf.dll
2014-12-10 17:06:33 ----A---- C:\Windows\system32\rrinstaller.exe
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mfps.dll
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mfpmp.exe
2014-12-10 17:06:33 ----A---- C:\Windows\system32\mferror.dll
2014-12-10 17:06:32 ----A---- C:\Windows\system32\mf.dll
2014-12-10 13:52:18 ----D---- C:\Users\f4r0\AppData\Roaming\Promotion Software GmbH
2014-12-10 10:30:24 ----A---- C:\Windows\system32\appraiser.dll
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aitstatic.exe
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aepic.dll
2014-12-10 10:30:24 ----A---- C:\Windows\system32\aeinv.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\invagent.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\generaltel.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\devinv.dll
2014-12-10 10:30:23 ----A---- C:\Windows\system32\aepdu.dll
2014-12-10 10:30:11 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2014-12-10 10:30:11 ----A---- C:\Windows\system32\WindowsCodecs.dll
2014-12-10 10:30:10 ----A---- C:\Windows\system32\drivers\tdx.sys
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2014-12-10 10:30:08 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\iernonce.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ieetwproxystub.dll
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ieetwcollector.exe
2014-12-10 10:30:08 ----A---- C:\Windows\system32\ie4uinit.exe
2014-12-10 10:30:07 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-12-10 10:30:07 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-12-10 10:30:06 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\urlmon.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2014-12-10 10:30:06 ----A---- C:\Windows\system32\iedkcs32.dll
2014-12-10 10:30:05 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-12-10 10:30:05 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-12-10 10:30:04 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\msfeeds.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\iesetup.dll
2014-12-10 10:30:04 ----A---- C:\Windows\system32\dxtrans.dll
2014-12-10 10:30:03 ----A---- C:\Windows\system32\iertutil.dll
2014-12-10 10:30:03 ----A---- C:\Windows\system32\ieapfltr.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2014-12-10 10:30:02 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2014-12-10 10:30:01 ----A---- C:\Windows\SYSWOW64\msrating.dll
2014-12-10 10:30:01 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2014-12-10 10:30:01 ----A---- C:\Windows\system32\jsproxy.dll
2014-12-10 10:30:01 ----A---- C:\Windows\system32\dxtmsft.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\mshtmlmedia.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\mshtmled.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\jscript9diag.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\jscript9.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\ieui.dll
2014-12-10 10:30:00 ----A---- C:\Windows\system32\ieframe.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\wininet.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\vbscript.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\msrating.dll
2014-12-10 10:29:59 ----A---- C:\Windows\system32\MshtmlDac.dll
2014-12-10 10:29:58 ----A---- C:\Windows\system32\mshtml.dll
2014-12-10 10:28:28 ----A---- C:\Windows\SYSWOW64\charmap.exe
2014-12-10 10:28:28 ----A---- C:\Windows\system32\charmap.exe
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2014-12-10 10:28:27 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmWmiPl.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmSvc.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WsmAuto.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-10 10:28:27 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2014-12-10 10:28:25 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-12-10 10:28:25 ----A---- C:\Windows\system32\tzres.dll
2014-12-10 02:29:24 ----D---- C:\ProgramData\ATI
2014-12-10 02:14:58 ----D---- C:\Program Files (x86)\AMD AVT
2014-12-10 02:12:06 ----D---- C:\Program Files (x86)\AMD
======List of files/folders modified in the last 1 month======
2015-01-09 14:13:22 ----D---- C:\Windows\Temp
2015-01-09 14:13:12 ----D---- C:\Users\f4r0\AppData\Roaming\uTorrent
2015-01-09 13:57:49 ----RD---- C:\Program Files
2015-01-09 12:21:50 ----D---- C:\Windows\system32\config
2015-01-09 12:08:46 ----RD---- C:\Program Files (x86)
2015-01-09 12:08:26 ----D---- C:\Windows
2015-01-09 12:06:08 ----D---- C:\ProgramData\Origin
2015-01-09 12:05:39 ----D---- C:\Program Files (x86)\Origin
2015-01-09 11:47:55 ----D---- C:\Windows\SysWOW64
2015-01-09 11:12:46 ----SHD---- C:\Windows\Installer
2015-01-09 11:12:26 ----D---- C:\Windows\system32\DriverStore
2015-01-09 11:12:26 ----D---- C:\Windows\system32\drivers
2015-01-09 11:12:26 ----D---- C:\Windows\system32\catroot
2015-01-09 11:12:26 ----D---- C:\Windows\inf
2015-01-09 11:11:52 ----HD---- C:\ProgramData
2015-01-09 11:02:53 ----D---- C:\Windows\Prefetch
2015-01-08 16:51:02 ----D---- C:\Windows\system32\Tasks
2015-01-08 16:51:01 ----D---- C:\Windows\Tasks
2015-01-08 16:51:01 ----D---- C:\Windows\AutoKMS
2015-01-08 16:51:00 ----D---- C:\Program Files\Common Files\System
2015-01-07 21:53:41 ----D---- C:\Windows\System32
2015-01-07 16:25:49 ----D---- C:\Program Files (x86)\Common Files
2015-01-06 04:36:02 ----N---- C:\Windows\system32\MpSigStub.exe
2015-01-05 18:30:47 ----D---- C:\Windows\SYSWOW64\GroupPolicy
2015-01-05 13:39:40 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2015-01-05 12:08:59 ----SD---- C:\Users\f4r0\AppData\Roaming\Microsoft
2015-01-04 11:36:04 ----D---- C:\Windows\SoftwareDistribution
2015-01-04 11:33:03 ----D---- C:\Users\f4r0\AppData\Roaming\DAEMON Tools Lite
2015-01-04 11:33:03 ----D---- C:\Program Files (x86)\Steam
2015-01-04 11:33:02 ----D---- C:\Windows\Logs
2015-01-03 19:22:01 ----D---- C:\Windows\SYSWOW64\directx
2015-01-03 15:16:16 ----D---- C:\Windows\winsxs
2015-01-03 15:06:16 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-12-30 21:53:07 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-12-29 11:58:51 ----D---- C:\Windows\system32\NDF
2014-12-29 11:57:46 ----SD---- C:\ProgramData\Microsoft
2014-12-27 12:52:38 ----D---- C:\Windows\Panther
2014-12-27 12:35:10 ----D---- C:\ProgramData\Ashampoo
2014-12-27 12:27:09 ----D---- C:\Users\f4r0\AppData\Roaming\Ashampoo
2014-12-26 22:03:48 ----D---- C:\Program Files (x86)\LG Electronics
2014-12-26 19:39:08 ----D---- C:\Users\f4r0\AppData\Roaming\.minecraft
2014-12-25 13:21:07 ----D---- C:\Users\f4r0\AppData\Roaming\Apple Computer
2014-12-25 13:20:13 ----D---- C:\ProgramData\Package Cache
2014-12-24 17:59:31 ----D---- C:\Windows\system32\catroot2
2014-12-23 15:17:59 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2014-12-19 22:27:23 ----D---- C:\Windows\Minidump
2014-12-19 10:21:52 ----D---- C:\Windows\system32\LogFiles
2014-12-18 12:00:44 ----D---- C:\Users\f4r0\AppData\Roaming\SpaceEngineers
2014-12-15 19:28:53 ----D---- C:\Program Files (x86)\epson
2014-12-15 18:33:54 ----D---- C:\ProgramData\EPSON
2014-12-15 18:33:21 ----D---- C:\Windows\twain_32
2014-12-15 17:05:54 ----D---- C:\Windows\system32\drivers\etc
2014-12-14 16:54:04 ----D---- C:\Windows\Cursors
2014-12-13 20:01:24 ----DC---- C:\Windows\system32\DRVSTORE
2014-12-13 20:01:05 ----D---- C:\Program Files\MKVToolNix
2014-12-13 15:11:01 ----D---- C:\Windows\rescache
2014-12-12 22:17:40 ----D---- C:\Windows\SYSWOW64\sk-SK
2014-12-12 22:17:40 ----D---- C:\Windows\system32\sk-SK
2014-12-11 11:56:07 ----D---- C:\Windows\debug
2014-12-10 18:08:01 ----SD---- C:\Windows\system32\CompatTel
2014-12-10 18:08:01 ----D---- C:\Windows\SYSWOW64\en-US
2014-12-10 18:08:01 ----D---- C:\Windows\system32\en-US
2014-12-10 18:08:01 ----D---- C:\Windows\PolicyDefinitions
2014-12-10 18:08:01 ----D---- C:\Windows\AppCompat
2014-12-10 18:08:01 ----D---- C:\Program Files\Internet Explorer
2014-12-10 18:08:00 ----D---- C:\Program Files (x86)\Internet Explorer
2014-12-10 17:11:45 ----D---- C:\Windows\system32\MRT
2014-12-10 17:08:54 ----A---- C:\Windows\system32\MRT.exe
2014-12-10 17:08:49 ----D---- C:\ProgramData\Microsoft Help
2014-12-10 16:26:27 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2014-12-10 02:33:29 ----D---- C:\Windows\Microsoft.NET
2014-12-10 02:14:59 ----D---- C:\ProgramData\AMD
2014-12-10 02:14:27 ----D---- C:\Program Files\AMD
2014-12-10 02:13:24 ----D---- C:\Program Files\ATI Technologies
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2014-10-10 63160]
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2014-12-16 118560]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2014-12-16 276256]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-01-30 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2014-10-10 243440]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2014-10-10 169280]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2014-10-10 44632]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2014-10-10 222280]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2014-11-21 18959360]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2014-11-21 589312]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2014-06-21 94720]
R3 BthEnum;Bluetooth Enumerator Service; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-06-19 4065296]
R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver; C:\Windows\system32\DRIVERS\nusb3hub.sys [2010-11-19 80384]
R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver; C:\Windows\system32\DRIVERS\nusb3xhc.sys [2010-11-19 181248]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2009-03-01 187392]
R3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S2 AODDriver4.2.0;AODDriver4.2.0; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys []
S3 andnetadb;ADB Interface DriverNet; C:\Windows\System32\Drivers\lgandnetadb.sys [2014-05-27 31744]
S3 AndnetBus;LGE Mobile USB Composite Device; C:\Windows\system32\DRIVERS\lgandnetbus64.sys [2014-05-27 20992]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\Windows\system32\DRIVERS\lgandnetdiag64.sys [2014-07-07 29184]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\Windows\system32\DRIVERS\lgandnetmodem64.sys [2014-07-07 36352]
S3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2012-08-30 1930240]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [2015-01-07 78088]
S3 Bridge;@%SystemRoot%\system32\bridgeres.dll,-3; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2014-01-23 108800]
S3 esgiguard;esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\esgiguard.sys [2014-01-07 14872]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys []
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2012-06-05 237968]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2014-01-23 206080]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbrndis6;USB RNDIS6 Adapter; C:\Windows\system32\DRIVERS\usb80236.sys [2013-02-12 19968]
S3 usbser;USB Modem Driver; C:\Windows\system32\drivers\usbser.sys [2013-08-29 33280]
S3 WinUsb;SAMSUNG Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2009-08-13 73984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2014-05-30 943136]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-03 81088]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2014-11-21 244736]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2014-10-07 60744]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2014-10-01 1349576]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2014-12-03 76152]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2014-10-15 643880]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-09-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-09-11 124088]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30 116648]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-10 267440]
S3 BRSptStub;BitRaider Mini-Support Service Stub Loader; C:\ProgramData\BitRaider\BRSptStub.exe [2015-01-07 363208]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-01-30 116648]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2014-11-22 114688]
S3 Installer Service;Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe [2014-09-03 125288]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 50942144]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2014-12-15 1903472]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2014-02-08 569024]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-12-15 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2013-09-11 51808]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2013-09-11 139856]
-----------------EOF-----------------
Re: dvojity ´´ ˇˇ
Zdravim
Od kdy problem pozorujete? ESET Smart Security jste dle logu nainstaloval dnes, tzn. do ted jste fungoval bez antiviru?
Pokud jeste v PC je, odinstalujte SpyHuntera.
Nainstalujte MBAM a udelejte vlastni sken vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=137928
- Upozorneni: tento sken zabere od 30 minut po nekolik hodin
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
spyhunter odinstalovany + som povyhadzoval nejake veci, co sa mi spustali po starte (co sa mi nezdali) a zda sa, ze problem vyrieseny. resp. ´ a ˇ idu normalne.
len mi zacalo vyskakovat toto okno po starte.

btw sken spusteny.
len mi zacalo vyskakovat toto okno po starte.

btw sken spusteny.
Re: dvojity ´´ ˇˇ
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
doteraz som fungoval na MSE a do teraz ziadny problem. dnes som nahodil ESET prave kvoli tomuto mojmu problemu.
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 9. 1. 2015
Čas skenování: 14:47:58
Protokol: mbam.sken.txt
Správce: Ano
Verze: 2.00.4.1028
Databáze malwaru: v2015.01.09.09
Databáze rootkitů: v2015.01.07.01
Licence: Premium
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: f4r0
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 474998
Uplynulý čas: 1 hod, 5 min, 34 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 0
(Žádné zákerné zjištěny položek)
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 0
(Žádné zákerné zjištěny položek)
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
Malwarebytes Anti-Malware
www.malwarebytes.org
Datum skenování: 9. 1. 2015
Čas skenování: 14:47:58
Protokol: mbam.sken.txt
Správce: Ano
Verze: 2.00.4.1028
Databáze malwaru: v2015.01.09.09
Databáze rootkitů: v2015.01.07.01
Licence: Premium
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Sebeobrany: Vypnuto
OS: Windows 7 Service Pack 1
CPU: x64
Souborový systém: NTFS
Uživatel: f4r0
Typ skenu: Vlastní sken
Výsledek: Dokončeno
Prohledaných objektů: 474998
Uplynulý čas: 1 hod, 5 min, 34 sek
Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Zapnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto
Procesy: 0
(Žádné zákerné zjištěny položek)
Moduly: 0
(Žádné zákerné zjištěny položek)
Klíče registru: 0
(Žádné zákerné zjištěny položek)
Hodnoty registru: 0
(Žádné zákerné zjištěny položek)
Data registru: 0
(Žádné zákerné zjištěny položek)
Složky: 0
(Žádné zákerné zjištěny položek)
Soubory: 0
(Žádné zákerné zjištěny položek)
Fyzické sektory: 0
(Žádné zákerné zjištěny položek)
(end)
Re: dvojity ´´ ˇˇ
- ukoncete vsechny programy
- kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
- kliknete na Scan, pote na Clean
- po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner [Sx].txt), jehoz obsah mi zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
# AdwCleaner v4.107 - Report created 10/01/2015 at 11:16:55
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : f4r0 - F4R0-PC
# Running from : C:\Users\f4r0\Desktop\adwcleaner_4.107.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found : C:\Users\f4r0\AppData\Local\CrashRpt
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R3].txt - [816 octets] - [10/01/2015 11:16:55]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [875 octets] ##########
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------
# AdwCleaner v4.107 - Report created 10/01/2015 at 11:23:27
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : f4r0 - F4R0-PC
# Running from : C:\Users\f4r0\Desktop\adwcleaner_4.107.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\f4r0\AppData\Local\CrashRpt
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Deleted : HKCU\Software\Conduit
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R3].txt - [962 octets] - [10/01/2015 11:16:55]
AdwCleaner[S1].txt - [845 octets] - [10/01/2015 11:23:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [904 octets] ##########
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : f4r0 - F4R0-PC
# Running from : C:\Users\f4r0\Desktop\adwcleaner_4.107.exe
# Option : Scan
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Found : C:\Users\f4r0\AppData\Local\CrashRpt
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Found : HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R3].txt - [816 octets] - [10/01/2015 11:16:55]
########## EOF - C:\AdwCleaner\AdwCleaner[R3].txt - [875 octets] ##########
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------
# AdwCleaner v4.107 - Report created 10/01/2015 at 11:23:27
# Updated 07/01/2015 by Xplode
# Database : 2015-01-03.1 [Live]
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : f4r0 - F4R0-PC
# Running from : C:\Users\f4r0\Desktop\adwcleaner_4.107.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Users\f4r0\AppData\Local\CrashRpt
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{020B1D4B-5738-4C77-9E19-4F173DD9B486}
Key Deleted : HKCU\Software\Conduit
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R3].txt - [962 octets] - [10/01/2015 11:16:55]
AdwCleaner[S1].txt - [845 octets] - [10/01/2015 11:23:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [904 octets] ##########
Re: dvojity ´´ ˇˇ
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015
Ran by f4r0 (administrator) on F4R0-PC on 10-01-2015 13:06:18
Running from C:\Users\f4r0\Desktop
Loaded Profile: f4r0 (Available profiles: f4r0)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Windows\System32\PnkBstrA.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(BitTorrent Inc.) C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [uTorrent] => C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-26] (BitTorrent Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-12-15] (Electronic Arts)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [5142664 2014-12-21] (Plex, Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\RunOnce: [Adobe Speed Launcher] => 1420885501
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {0d9a749c-899d-11e3-b382-000272a6c7a3} - G:\setup.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {d2ce7013-abaa-11e3-bca9-000272a6c7a3} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {e443e277-4ada-11e4-9f50-1c6f65893f0a} - I:\LG_PC_Programs.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2804201978-2127736804-1701630455-1000 -> {217CBE9B-0BE5-4671-BEF2-613B69BCF53C} URL = https://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.1.1.100
FireFox:
========
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.sk/
CHR StartupUrls: Default -> "hxxp://www.google.sk/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Brushed) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2014-01-30]
CHR Extension: (vGet Cast (DLNA Controller)) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjofnchpbfmnfbedalmbdlhbabiapi [2014-12-29]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2014-12-15]
CHR Extension: (Pastebin.com) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghipmampnddcpdlppkkamoankmkmcbmh [2014-12-15]
CHR Extension: (AdBlock) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-12-15]
CHR Extension: (Peňaženka Google) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-01-07] (BitRaider, LLC)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe [125288 2014-09-03] ()
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2014-12-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-12-03] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-06-25] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc)
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-01-07] (BitRaider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-01-30] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
U3 DfSdkS; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-10 13:06 - 2015-01-10 13:06 - 00014655 _____ () C:\Users\f4r0\Desktop\FRST.txt
2015-01-10 13:05 - 2015-01-10 13:06 - 00000000 ____D () C:\FRST
2015-01-10 13:03 - 2015-01-10 13:04 - 00112640 _____ (forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
2015-01-10 13:03 - 2015-01-10 13:03 - 02124288 _____ (Farbar) C:\Users\f4r0\Desktop\FRST64.exe
2015-01-10 11:56 - 2015-01-10 11:56 - 00000577 _____ () C:\Users\f4r0\Desktop\[CzT]Kod_Enigmy_The_Imitation_Game_2014_CZ_titulky.torrent
2015-01-10 11:16 - 2015-01-10 11:23 - 00000000 ____D () C:\AdwCleaner
2015-01-09 14:46 - 2015-01-09 17:41 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-09 14:45 - 2015-01-09 14:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-09 14:45 - 2015-01-09 14:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-09 14:45 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-09 14:45 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-09 14:45 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-09 14:39 - 2015-01-09 14:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2015-01-09 13:57 - 2015-01-09 14:13 - 00000000 ____D () C:\Program Files\trend micro
2015-01-09 12:32 - 2015-01-09 12:32 - 00033280 _____ () C:\Users\f4r0\Desktop\petrikova.xls
2015-01-09 11:47 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\SysWOW64\sh4native.exe
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\ProgramData\ESET
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\Program Files\ESET
2015-01-08 11:40 - 2015-01-08 11:40 - 00046080 _____ () C:\Users\f4r0\Desktop\Luščon vývozy.xls
2015-01-07 23:40 - 2015-01-07 23:40 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SWTOR
2015-01-07 23:32 - 2015-01-07 23:31 - 00000989 _____ () C:\Users\f4r0\Desktop\PE_Launcher.lnk
2015-01-07 23:31 - 2015-01-07 23:35 - 00000000 ____D () C:\Users\f4r0\Documents\PlanetExplorers
2015-01-07 21:54 - 2015-01-07 21:56 - 00000000 ____D () C:\ProgramData\htpc
2015-01-07 21:53 - 2015-01-07 21:53 - 00000984 _____ () C:\Windows\system32\parent.lnk
2015-01-07 21:53 - 2015-01-07 21:53 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Parental Controls
2015-01-07 17:00 - 2015-01-07 17:07 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\avidemux
2015-01-07 16:59 - 2015-01-07 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)
2015-01-07 16:59 - 2015-01-07 16:59 - 00000000 ____D () C:\Program Files\Avidemux 2.6 - 64bits
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SWTORPerf
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\ProgramData\BitRaider
2015-01-07 16:25 - 2015-01-07 16:25 - 00000772 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2015-01-07 16:25 - 2015-01-07 16:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2015-01-07 16:23 - 2015-01-07 16:25 - 00018064 _____ () C:\Users\f4r0\Documents\Install STAR WARS The Old Republic.log
2015-01-07 14:17 - 2015-01-07 14:17 - 00000577 _____ () C:\Users\Public\Desktop\Ryse Son of Rome.lnk
2015-01-07 14:17 - 2015-01-07 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ryse Son of Rome
2015-01-06 15:54 - 2015-01-06 15:54 - 00000000 ____D () C:\Users\f4r0\Documents\Paradox Interactive
2015-01-06 15:53 - 2015-01-06 15:53 - 00000739 _____ () C:\Users\Public\Desktop\Crusader Kings II Way of Life.lnk
2015-01-06 15:53 - 2015-01-06 15:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive
2015-01-06 15:29 - 2015-01-06 15:29 - 00162355 _____ () C:\Users\f4r0\Desktop\fuxoft_zx.zip
2015-01-05 18:30 - 2015-01-05 18:30 - 00000000 ____D () C:\Windows\SysWOW64\GPBAK
2015-01-05 18:30 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll
2015-01-05 18:30 - 2001-08-23 13:00 - 00034871 _____ () C:\Windows\SysWOW64\gpedit.msc
2015-01-05 14:33 - 2015-01-05 14:33 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\AutoHideIP
2015-01-05 14:33 - 2015-01-05 14:33 - 00000000 ____D () C:\ProgramData\AutoHideIP
2015-01-04 21:56 - 2015-01-04 22:01 - 00000000 ____D () C:\Fraps
2015-01-04 21:56 - 2015-01-04 21:56 - 00000568 _____ () C:\Users\Public\Desktop\Fraps.lnk
2015-01-04 21:56 - 2015-01-04 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2015-01-03 22:20 - 2015-01-03 22:20 - 00000599 _____ () C:\Users\Public\Desktop\Worms Clan Wars.lnk
2015-01-03 22:20 - 2015-01-03 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Team 17
2015-01-03 21:00 - 2015-01-03 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2015-01-03 20:25 - 2015-01-03 18:41 - 00000477 _____ () C:\Users\f4r0\Desktop\Skyrim.lnk
2015-01-03 19:26 - 2015-01-03 21:00 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Black_Tree_Gaming
2015-01-03 19:26 - 2015-01-03 19:26 - 00000000 ____D () C:\Users\f4r0\Documents\Nexus Mod Manager
2015-01-03 19:11 - 2015-01-03 19:11 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Skyrim
2015-01-02 20:15 - 2015-01-02 20:15 - 00000475 _____ () C:\Users\Public\Desktop\Fireworks Simulator.lnk
2015-01-02 20:15 - 2015-01-02 20:15 - 00000475 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fireworks Simulator.lnk
2014-12-29 13:04 - 2014-12-29 13:04 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-29 13:04 - 2014-12-29 13:04 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome
2014-12-29 11:01 - 2014-12-29 11:02 - 00000000 ____D () C:\Users\f4r0\Desktop\Ashampoo pack
2014-12-28 15:48 - 2014-12-28 15:48 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Frontier Developments
2014-12-28 15:48 - 2014-12-28 15:48 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Frontier Developments
2014-12-27 12:35 - 2009-08-24 22:13 - 00034304 _____ (mst software GmbH, Germany) C:\Windows\system32\DfSdkBt.exe
2014-12-27 12:26 - 2014-12-28 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-12-27 12:26 - 2014-12-28 10:50 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-12-26 22:06 - 2014-12-26 22:06 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\LG Electronics
2014-12-26 22:04 - 2014-12-26 22:04 - 00000000 ____D () C:\Users\f4r0\AppData\Local\LG Electronics
2014-12-26 22:04 - 2014-12-26 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG PC Suite
2014-12-26 00:27 - 2014-12-26 00:27 - 00000917 _____ () C:\Users\f4r0\Desktop\TheForest.lnk
2014-12-25 13:20 - 2014-12-25 13:26 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Plex Media Server
2014-12-25 13:20 - 2014-12-25 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2014-12-25 13:20 - 2014-12-25 13:20 - 00000000 ____D () C:\Program Files (x86)\Plex
2014-12-24 20:59 - 2014-12-24 22:22 - 00000000 ____D () C:\Users\f4r0\Documents\FIFA 15
2014-12-24 20:34 - 2014-12-24 20:44 - 00000669 _____ () C:\Users\Public\Desktop\FIFA 15.lnk
2014-12-24 20:34 - 2014-12-24 20:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15
2014-12-24 20:10 - 2015-01-09 17:40 - 00000000 ____D () C:\Users\f4r0\Desktop\Hevier
2014-12-23 16:40 - 2014-12-23 16:40 - 00002562 _____ () C:\Windows\diagwrn.xml
2014-12-23 16:40 - 2014-12-23 16:40 - 00001908 _____ () C:\Windows\diagerr.xml
2014-12-22 12:57 - 2014-12-22 12:57 - 00000642 _____ () C:\Users\f4r0\Desktop\Run Ski Challenge 15.lnk
2014-12-22 12:57 - 2014-12-22 12:57 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ski Challenge 15
2014-12-21 13:57 - 2014-12-21 13:57 - 00000000 ____D () C:\Users\f4r0\Documents\Telltale Games
2014-12-21 13:04 - 2014-12-21 13:04 - 00000655 _____ () C:\Users\Public\Desktop\The Walking Dead Season 2.lnk
2014-12-21 13:04 - 2014-12-21 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2
2014-12-18 11:24 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 11:24 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 10:00 - 2014-12-17 10:00 - 00000000 __SHD () C:\found.000
2014-12-16 21:59 - 2014-12-16 22:13 - 00000000 ____D () C:\Users\f4r0\Documents\TransOcean
2014-12-16 21:49 - 2014-12-16 21:49 - 00000680 _____ () C:\Users\Public\Desktop\TransOcean - The Shipping Company.lnk
2014-12-16 21:49 - 2014-12-16 21:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deck 13
2014-12-16 21:00 - 2014-12-18 20:36 - 00000000 ____D () C:\Windows\Acronis
2014-12-16 21:00 - 2014-12-16 21:00 - 00000161 _____ () C:\Windows\system32\autopart.opt
2014-12-16 20:56 - 2014-12-16 20:56 - 00000000 ____D () C:\ProgramData\Acronis
2014-12-16 20:55 - 2014-12-16 20:55 - 00276256 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys
2014-12-16 20:55 - 2014-12-16 20:55 - 00118560 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys
2014-12-16 20:55 - 2014-12-16 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
2014-12-16 20:55 - 2014-12-16 20:55 - 00000000 ____D () C:\Program Files (x86)\Acronis
2014-12-16 18:48 - 2014-12-16 18:48 - 00000868 _____ () C:\Users\Public\Desktop\Sherlock Holmes Zločin a trest.lnk
2014-12-16 18:48 - 2014-12-16 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REPACK BY TOMI2K9
2014-12-15 18:19 - 2014-12-15 18:32 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\mIRC
2014-12-15 17:44 - 2014-12-15 17:44 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Miranda
2014-12-15 17:43 - 2014-12-15 18:34 - 00000000 ____D () C:\Program Files (x86)\Miranda IM
2014-12-15 17:42 - 2014-12-15 17:41 - 07973951 _____ (Miranda IM Project) C:\Users\f4r0\Downloads\miranda-im-v0.10.27-unicode [1].exe
2014-12-14 15:30 - 2015-01-09 14:39 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-12-14 15:30 - 2014-12-14 15:30 - 00000000 _____ () C:\autoexec.bat
2014-12-14 15:22 - 2014-12-14 15:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-14 14:40 - 2014-12-14 14:40 - 00000000 ____D () C:\Windows\ERUNT
2014-12-13 12:46 - 2014-12-13 12:46 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\AMD
2014-12-12 20:23 - 2014-12-12 20:23 - 00000619 _____ () C:\Users\f4r0\Desktop\This War of Mine.lnk
2014-12-12 20:23 - 2014-12-12 20:23 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\11bitstudios
2014-12-12 20:21 - 2014-12-12 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-12-12 20:21 - 2014-12-12 20:21 - 00000000 ____D () C:\Program Files\7-Zip
2014-12-11 19:29 - 2014-12-11 19:29 - 00177152 _____ () C:\Users\f4r0\Desktop\JoJ_struktura_first_month_version11.12..2014.xls
2014-12-11 19:29 - 2014-12-11 19:29 - 00023333 _____ () C:\Users\f4r0\Desktop\Textová časť.htm
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-10 13:05 - 2014-01-30 12:01 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\uTorrent
2015-01-10 12:41 - 2014-01-30 11:38 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-10 12:26 - 2014-05-04 10:51 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-10 12:05 - 2014-01-30 11:13 - 01776940 _____ () C:\Windows\WindowsUpdate.log
2015-01-10 11:32 - 2009-07-14 05:45 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-10 11:32 - 2009-07-14 05:45 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-10 11:25 - 2014-01-30 12:52 - 00000000 ____D () C:\ProgramData\Origin
2015-01-10 11:24 - 2014-01-30 12:51 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-10 11:24 - 2014-01-30 11:43 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job
2015-01-10 11:24 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-09 17:37 - 2014-03-14 14:16 - 00000000 ____D () C:\Users\f4r0\Documents\Súbory programu Outlook
2015-01-09 12:59 - 2014-08-29 14:01 - 00000000 ____D () C:\Users\f4r0\Desktop\erika
2015-01-09 10:57 - 2014-01-30 15:19 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-01-08 16:51 - 2014-03-14 14:08 - 00000000 ____D () C:\Windows\AutoKMS
2015-01-08 16:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-08 14:46 - 2014-02-06 12:41 - 00001309 _____ () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk
2015-01-07 16:25 - 2014-11-19 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-01-07 16:25 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-07 13:45 - 2014-02-26 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2015-01-06 15:54 - 2014-10-08 15:32 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SKIDROW
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-01-05 13:39 - 2014-05-08 08:22 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-05 13:28 - 2014-05-08 08:22 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-04 11:33 - 2014-03-29 15:41 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-04 11:33 - 2014-01-30 12:14 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\DAEMON Tools Lite
2015-01-03 19:22 - 2014-03-09 17:13 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-03 19:11 - 2014-03-16 15:36 - 00000000 ____D () C:\Users\f4r0\Documents\My Games
2015-01-03 15:06 - 2014-03-09 14:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-12-30 21:53 - 2009-07-14 06:13 - 00785302 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-30 16:53 - 2009-07-14 06:08 - 00032552 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-29 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-29 11:57 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-12-27 20:56 - 2014-03-31 17:36 - 00000000 ____D () C:\Users\f4r0\.gimp-2.8
2014-12-27 20:53 - 2014-03-31 17:35 - 00001126 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-12-27 12:52 - 2014-01-30 11:08 - 00000000 ____D () C:\Windows\Panther
2014-12-27 12:35 - 2014-04-15 09:15 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-12-27 12:27 - 2014-04-15 09:27 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Ashampoo
2014-12-26 22:03 - 2014-10-20 08:28 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-12-26 19:39 - 2014-10-18 09:15 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\.minecraft
2014-12-25 13:21 - 2014-11-23 22:14 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Apple Computer
2014-12-25 13:20 - 2014-01-30 12:17 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-24 15:12 - 2014-01-30 15:32 - 00000000 ____D () C:\Users\f4r0\Documents\FIFA 14
2014-12-23 15:17 - 2014-05-08 08:22 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-12-19 22:27 - 2014-02-27 15:44 - 00000000 ____D () C:\Windows\Minidump
2014-12-18 12:00 - 2014-03-25 16:57 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\SpaceEngineers
2014-12-15 19:28 - 2014-11-12 23:07 - 00000000 ____D () C:\Program Files (x86)\epson
2014-12-15 18:33 - 2014-11-12 21:55 - 00000000 ____D () C:\ProgramData\EPSON
2014-12-14 16:54 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors
2014-12-14 14:36 - 2014-11-12 19:12 - 00000867 _____ () C:\Users\f4r0\Desktop\Sweet Home 3D.lnk
2014-12-14 14:36 - 2014-11-12 19:12 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D
2014-12-13 20:01 - 2014-05-04 09:54 - 00000000 ____D () C:\Program Files\MKVToolNix
2014-12-13 19:56 - 2014-03-29 09:51 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-13 15:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 22:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK
2014-12-12 22:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sk-SK
Some content of TEMP:
====================
C:\Users\f4r0\AppData\Local\Temp\InstHelper.exe
C:\Users\f4r0\AppData\Local\Temp\Quarantine.exe
C:\Users\f4r0\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 13:20
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (System) (Fixed) (Total:99.03 GB) (Free:47.45 GB) NTFS
Drive d: (Games) (Fixed) (Total:290.7 GB) (Free:20.73 GB) NTFS
Drive e: (Store) (Fixed) (Total:541.67 GB) (Free:111.53 GB) NTFS
Drive g: (Worms Clan Wars) (CDROM) (Total:1.35 GB) (Free:0 GB) CDFS
Available physical RAM: 5831.72 MB
Total physical RAM: 8189.55 MB
Percentage of memory in use: 28%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 931.5 GB) (Disk ID: 0004672C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=99 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=290.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=541.7 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:DEDEE4A9
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personálny Firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\f4r0\Desktop" je 656 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by f4r0 (administrator) on F4R0-PC on 10-01-2015 13:06:18
Running from C:\Users\f4r0\Desktop
Loaded Profile: f4r0 (Available profiles: f4r0)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Windows\System32\PnkBstrA.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(BitTorrent Inc.) C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe
(Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe
(Python Software Foundation) C:\Program Files (x86)\Plex\Plex Media Server\PlexScriptHost.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Plex, Inc.) C:\Program Files (x86)\Plex\Plex Media Server\PlexDlnaServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5595336 2014-10-01] (ESET)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [uTorrent] => C:\Users\f4r0\AppData\Roaming\uTorrent\uTorrent.exe [1385808 2014-11-26] (BitTorrent Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3618648 2014-12-15] (Electronic Arts)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [5142664 2014-12-21] (Plex, Inc.)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\RunOnce: [Adobe Speed Launcher] => 1420885501
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {0d9a749c-899d-11e3-b382-000272a6c7a3} - G:\setup.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {d2ce7013-abaa-11e3-bca9-000272a6c7a3} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {e443e277-4ada-11e4-9f50-1c6f65893f0a} - I:\LG_PC_Programs.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2804201978-2127736804-1701630455-1000 -> {217CBE9B-0BE5-4671-BEF2-613B69BCF53C} URL = https://www.google.com/search?q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.1.1.100
FireFox:
========
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.sk/
CHR StartupUrls: Default -> "hxxp://www.google.sk/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Brushed) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfjgbcjfpbbfepcccpaffkjofcmglifg [2014-01-30]
CHR Extension: (vGet Cast (DLNA Controller)) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjofnchpbfmnfbedalmbdlhbabiapi [2014-12-29]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2014-12-15]
CHR Extension: (Pastebin.com) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghipmampnddcpdlppkkamoankmkmcbmh [2014-12-15]
CHR Extension: (AdBlock) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-12-15]
CHR Extension: (Peňaženka Google) - C:\Users\f4r0\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-30]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-01-07] (BitRaider, LLC)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1349576 2014-10-01] (ESET)
S3 Installer Service; C:\ProgramData\NokiaInstallerCache\ProductCache\{D5878294-C113-43c5-A24F-FC333C52015A}\{EDB188F5-D8E8-42EE-89E0-F212DA48CB81}\Installer\InstallerService.exe [125288 2014-09-03] ()
S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1903472 2014-12-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2014-12-03] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2014-06-25] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc)
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-01-07] (BitRaider)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-01-30] (Disc Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [243440 2014-10-10] (ESET)
U5 edevmon; C:\Windows\System32\Drivers\edevmon.sys [241368 2014-10-10] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [169280 2014-10-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [222280 2014-10-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [44632 2014-10-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [63160 2014-10-10] (ESET)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
U3 DfSdkS; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-10 13:06 - 2015-01-10 13:06 - 00014655 _____ () C:\Users\f4r0\Desktop\FRST.txt
2015-01-10 13:05 - 2015-01-10 13:06 - 00000000 ____D () C:\FRST
2015-01-10 13:03 - 2015-01-10 13:04 - 00112640 _____ (forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
2015-01-10 13:03 - 2015-01-10 13:03 - 02124288 _____ (Farbar) C:\Users\f4r0\Desktop\FRST64.exe
2015-01-10 11:56 - 2015-01-10 11:56 - 00000577 _____ () C:\Users\f4r0\Desktop\[CzT]Kod_Enigmy_The_Imitation_Game_2014_CZ_titulky.torrent
2015-01-10 11:16 - 2015-01-10 11:23 - 00000000 ____D () C:\AdwCleaner
2015-01-09 14:46 - 2015-01-09 17:41 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-09 14:45 - 2015-01-09 14:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-09 14:45 - 2015-01-09 14:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-09 14:45 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-09 14:45 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-01-09 14:45 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-01-09 14:39 - 2015-01-09 14:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2015-01-09 13:57 - 2015-01-09 14:13 - 00000000 ____D () C:\Program Files\trend micro
2015-01-09 12:32 - 2015-01-09 12:32 - 00033280 _____ () C:\Users\f4r0\Desktop\petrikova.xls
2015-01-09 11:47 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\SysWOW64\sh4native.exe
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\ProgramData\ESET
2015-01-09 11:11 - 2015-01-09 11:11 - 00000000 ____D () C:\Program Files\ESET
2015-01-08 11:40 - 2015-01-08 11:40 - 00046080 _____ () C:\Users\f4r0\Desktop\Luščon vývozy.xls
2015-01-07 23:40 - 2015-01-07 23:40 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SWTOR
2015-01-07 23:32 - 2015-01-07 23:31 - 00000989 _____ () C:\Users\f4r0\Desktop\PE_Launcher.lnk
2015-01-07 23:31 - 2015-01-07 23:35 - 00000000 ____D () C:\Users\f4r0\Documents\PlanetExplorers
2015-01-07 21:54 - 2015-01-07 21:56 - 00000000 ____D () C:\ProgramData\htpc
2015-01-07 21:53 - 2015-01-07 21:53 - 00000984 _____ () C:\Windows\system32\parent.lnk
2015-01-07 21:53 - 2015-01-07 21:53 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Parental Controls
2015-01-07 17:00 - 2015-01-07 17:07 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\avidemux
2015-01-07 16:59 - 2015-01-07 16:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avidemux (64bits)
2015-01-07 16:59 - 2015-01-07 16:59 - 00000000 ____D () C:\Program Files\Avidemux 2.6 - 64bits
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\Users\Public\Documents\BitRaider
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SWTORPerf
2015-01-07 16:37 - 2015-01-07 16:37 - 00000000 ____D () C:\ProgramData\BitRaider
2015-01-07 16:25 - 2015-01-07 16:25 - 00000772 _____ () C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
2015-01-07 16:25 - 2015-01-07 16:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA
2015-01-07 16:23 - 2015-01-07 16:25 - 00018064 _____ () C:\Users\f4r0\Documents\Install STAR WARS The Old Republic.log
2015-01-07 14:17 - 2015-01-07 14:17 - 00000577 _____ () C:\Users\Public\Desktop\Ryse Son of Rome.lnk
2015-01-07 14:17 - 2015-01-07 14:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ryse Son of Rome
2015-01-06 15:54 - 2015-01-06 15:54 - 00000000 ____D () C:\Users\f4r0\Documents\Paradox Interactive
2015-01-06 15:53 - 2015-01-06 15:53 - 00000739 _____ () C:\Users\Public\Desktop\Crusader Kings II Way of Life.lnk
2015-01-06 15:53 - 2015-01-06 15:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive
2015-01-06 15:29 - 2015-01-06 15:29 - 00162355 _____ () C:\Users\f4r0\Desktop\fuxoft_zx.zip
2015-01-05 18:30 - 2015-01-05 18:30 - 00000000 ____D () C:\Windows\SysWOW64\GPBAK
2015-01-05 18:30 - 2008-04-14 02:11 - 00295936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appmgr.dll
2015-01-05 18:30 - 2001-08-23 13:00 - 00034871 _____ () C:\Windows\SysWOW64\gpedit.msc
2015-01-05 14:33 - 2015-01-05 14:33 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\AutoHideIP
2015-01-05 14:33 - 2015-01-05 14:33 - 00000000 ____D () C:\ProgramData\AutoHideIP
2015-01-04 21:56 - 2015-01-04 22:01 - 00000000 ____D () C:\Fraps
2015-01-04 21:56 - 2015-01-04 21:56 - 00000568 _____ () C:\Users\Public\Desktop\Fraps.lnk
2015-01-04 21:56 - 2015-01-04 21:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2015-01-03 22:20 - 2015-01-03 22:20 - 00000599 _____ () C:\Users\Public\Desktop\Worms Clan Wars.lnk
2015-01-03 22:20 - 2015-01-03 22:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Team 17
2015-01-03 21:00 - 2015-01-03 21:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2015-01-03 20:25 - 2015-01-03 18:41 - 00000477 _____ () C:\Users\f4r0\Desktop\Skyrim.lnk
2015-01-03 19:26 - 2015-01-03 21:00 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Black_Tree_Gaming
2015-01-03 19:26 - 2015-01-03 19:26 - 00000000 ____D () C:\Users\f4r0\Documents\Nexus Mod Manager
2015-01-03 19:11 - 2015-01-03 19:11 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Skyrim
2015-01-02 20:15 - 2015-01-02 20:15 - 00000475 _____ () C:\Users\Public\Desktop\Fireworks Simulator.lnk
2015-01-02 20:15 - 2015-01-02 20:15 - 00000475 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fireworks Simulator.lnk
2014-12-29 13:04 - 2014-12-29 13:04 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-29 13:04 - 2014-12-29 13:04 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome
2014-12-29 11:01 - 2014-12-29 11:02 - 00000000 ____D () C:\Users\f4r0\Desktop\Ashampoo pack
2014-12-28 15:48 - 2014-12-28 15:48 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Frontier Developments
2014-12-28 15:48 - 2014-12-28 15:48 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Frontier Developments
2014-12-27 12:35 - 2009-08-24 22:13 - 00034304 _____ (mst software GmbH, Germany) C:\Windows\system32\DfSdkBt.exe
2014-12-27 12:26 - 2014-12-28 10:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2014-12-27 12:26 - 2014-12-28 10:50 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-12-26 22:06 - 2014-12-26 22:06 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\LG Electronics
2014-12-26 22:04 - 2014-12-26 22:04 - 00000000 ____D () C:\Users\f4r0\AppData\Local\LG Electronics
2014-12-26 22:04 - 2014-12-26 22:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LG PC Suite
2014-12-26 00:27 - 2014-12-26 00:27 - 00000917 _____ () C:\Users\f4r0\Desktop\TheForest.lnk
2014-12-25 13:20 - 2014-12-25 13:26 - 00000000 ____D () C:\Users\f4r0\AppData\Local\Plex Media Server
2014-12-25 13:20 - 2014-12-25 13:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2014-12-25 13:20 - 2014-12-25 13:20 - 00000000 ____D () C:\Program Files (x86)\Plex
2014-12-24 20:59 - 2014-12-24 22:22 - 00000000 ____D () C:\Users\f4r0\Documents\FIFA 15
2014-12-24 20:34 - 2014-12-24 20:44 - 00000669 _____ () C:\Users\Public\Desktop\FIFA 15.lnk
2014-12-24 20:34 - 2014-12-24 20:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15
2014-12-24 20:10 - 2015-01-09 17:40 - 00000000 ____D () C:\Users\f4r0\Desktop\Hevier
2014-12-23 16:40 - 2014-12-23 16:40 - 00002562 _____ () C:\Windows\diagwrn.xml
2014-12-23 16:40 - 2014-12-23 16:40 - 00001908 _____ () C:\Windows\diagerr.xml
2014-12-22 12:57 - 2014-12-22 12:57 - 00000642 _____ () C:\Users\f4r0\Desktop\Run Ski Challenge 15.lnk
2014-12-22 12:57 - 2014-12-22 12:57 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ski Challenge 15
2014-12-21 13:57 - 2014-12-21 13:57 - 00000000 ____D () C:\Users\f4r0\Documents\Telltale Games
2014-12-21 13:04 - 2014-12-21 13:04 - 00000655 _____ () C:\Users\Public\Desktop\The Walking Dead Season 2.lnk
2014-12-21 13:04 - 2014-12-21 13:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Walking Dead Season 2
2014-12-18 11:24 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 11:24 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 10:00 - 2014-12-17 10:00 - 00000000 __SHD () C:\found.000
2014-12-16 21:59 - 2014-12-16 22:13 - 00000000 ____D () C:\Users\f4r0\Documents\TransOcean
2014-12-16 21:49 - 2014-12-16 21:49 - 00000680 _____ () C:\Users\Public\Desktop\TransOcean - The Shipping Company.lnk
2014-12-16 21:49 - 2014-12-16 21:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deck 13
2014-12-16 21:00 - 2014-12-18 20:36 - 00000000 ____D () C:\Windows\Acronis
2014-12-16 21:00 - 2014-12-16 21:00 - 00000161 _____ () C:\Windows\system32\autopart.opt
2014-12-16 20:56 - 2014-12-16 20:56 - 00000000 ____D () C:\ProgramData\Acronis
2014-12-16 20:55 - 2014-12-16 20:55 - 00276256 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\snapman.sys
2014-12-16 20:55 - 2014-12-16 20:55 - 00118560 _____ (Acronis International GmbH) C:\Windows\system32\Drivers\fltsrv.sys
2014-12-16 20:55 - 2014-12-16 20:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acronis
2014-12-16 20:55 - 2014-12-16 20:55 - 00000000 ____D () C:\Program Files (x86)\Acronis
2014-12-16 18:48 - 2014-12-16 18:48 - 00000868 _____ () C:\Users\Public\Desktop\Sherlock Holmes Zločin a trest.lnk
2014-12-16 18:48 - 2014-12-16 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REPACK BY TOMI2K9
2014-12-15 18:19 - 2014-12-15 18:32 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\mIRC
2014-12-15 17:44 - 2014-12-15 17:44 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Miranda
2014-12-15 17:43 - 2014-12-15 18:34 - 00000000 ____D () C:\Program Files (x86)\Miranda IM
2014-12-15 17:42 - 2014-12-15 17:41 - 07973951 _____ (Miranda IM Project) C:\Users\f4r0\Downloads\miranda-im-v0.10.27-unicode [1].exe
2014-12-14 15:30 - 2015-01-09 14:39 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2014-12-14 15:30 - 2014-12-14 15:30 - 00000000 _____ () C:\autoexec.bat
2014-12-14 15:22 - 2014-12-14 15:22 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-14 14:40 - 2014-12-14 14:40 - 00000000 ____D () C:\Windows\ERUNT
2014-12-13 12:46 - 2014-12-13 12:46 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\AMD
2014-12-12 20:23 - 2014-12-12 20:23 - 00000619 _____ () C:\Users\f4r0\Desktop\This War of Mine.lnk
2014-12-12 20:23 - 2014-12-12 20:23 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\11bitstudios
2014-12-12 20:21 - 2014-12-12 20:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-12-12 20:21 - 2014-12-12 20:21 - 00000000 ____D () C:\Program Files\7-Zip
2014-12-11 19:29 - 2014-12-11 19:29 - 00177152 _____ () C:\Users\f4r0\Desktop\JoJ_struktura_first_month_version11.12..2014.xls
2014-12-11 19:29 - 2014-12-11 19:29 - 00023333 _____ () C:\Users\f4r0\Desktop\Textová časť.htm
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-10 13:05 - 2014-01-30 12:01 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\uTorrent
2015-01-10 12:41 - 2014-01-30 11:38 - 00000936 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-10 12:26 - 2014-05-04 10:51 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-10 12:05 - 2014-01-30 11:13 - 01776940 _____ () C:\Windows\WindowsUpdate.log
2015-01-10 11:32 - 2009-07-14 05:45 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-10 11:32 - 2009-07-14 05:45 - 00030960 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-10 11:25 - 2014-01-30 12:52 - 00000000 ____D () C:\ProgramData\Origin
2015-01-10 11:24 - 2014-01-30 12:51 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-10 11:24 - 2014-01-30 11:43 - 00000932 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job
2015-01-10 11:24 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-09 17:37 - 2014-03-14 14:16 - 00000000 ____D () C:\Users\f4r0\Documents\Súbory programu Outlook
2015-01-09 12:59 - 2014-08-29 14:01 - 00000000 ____D () C:\Users\f4r0\Desktop\erika
2015-01-09 10:57 - 2014-01-30 15:19 - 00001912 _____ () C:\Windows\epplauncher.mif
2015-01-08 16:51 - 2014-03-14 14:08 - 00000000 ____D () C:\Windows\AutoKMS
2015-01-08 16:51 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-08 14:46 - 2014-02-06 12:41 - 00001309 _____ () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk
2015-01-07 16:25 - 2014-11-19 18:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-01-07 16:25 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-01-07 13:45 - 2014-02-26 13:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hry
2015-01-06 15:54 - 2014-10-08 15:32 - 00000000 ____D () C:\Users\f4r0\AppData\Local\SKIDROW
2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 18:30 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2015-01-05 13:39 - 2014-05-08 08:22 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-01-05 13:28 - 2014-05-08 08:22 - 00215416 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-01-04 11:33 - 2014-03-29 15:41 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-01-04 11:33 - 2014-01-30 12:14 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\DAEMON Tools Lite
2015-01-03 19:22 - 2014-03-09 17:13 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-01-03 19:11 - 2014-03-16 15:36 - 00000000 ____D () C:\Users\f4r0\Documents\My Games
2015-01-03 15:06 - 2014-03-09 14:56 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-12-30 21:53 - 2009-07-14 06:13 - 00785302 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-30 16:53 - 2009-07-14 06:08 - 00032552 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-12-29 11:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-12-29 11:57 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-12-27 20:56 - 2014-03-31 17:36 - 00000000 ____D () C:\Users\f4r0\.gimp-2.8
2014-12-27 20:53 - 2014-03-31 17:35 - 00001126 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2014-12-27 12:52 - 2014-01-30 11:08 - 00000000 ____D () C:\Windows\Panther
2014-12-27 12:35 - 2014-04-15 09:15 - 00000000 ____D () C:\ProgramData\Ashampoo
2014-12-27 12:27 - 2014-04-15 09:27 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Ashampoo
2014-12-26 22:03 - 2014-10-20 08:28 - 00000000 ____D () C:\Program Files (x86)\LG Electronics
2014-12-26 19:39 - 2014-10-18 09:15 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\.minecraft
2014-12-25 13:21 - 2014-11-23 22:14 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Apple Computer
2014-12-25 13:20 - 2014-01-30 12:17 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-24 15:12 - 2014-01-30 15:32 - 00000000 ____D () C:\Users\f4r0\Documents\FIFA 14
2014-12-23 15:17 - 2014-05-08 08:22 - 00000000 ____D () C:\Program Files (x86)\Battlelog Web Plugins
2014-12-19 22:27 - 2014-02-27 15:44 - 00000000 ____D () C:\Windows\Minidump
2014-12-18 12:00 - 2014-03-25 16:57 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\SpaceEngineers
2014-12-15 19:28 - 2014-11-12 23:07 - 00000000 ____D () C:\Program Files (x86)\epson
2014-12-15 18:33 - 2014-11-12 21:55 - 00000000 ____D () C:\ProgramData\EPSON
2014-12-14 16:54 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\Cursors
2014-12-14 14:36 - 2014-11-12 19:12 - 00000867 _____ () C:\Users\f4r0\Desktop\Sweet Home 3D.lnk
2014-12-14 14:36 - 2014-11-12 19:12 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\eTeks Sweet Home 3D
2014-12-13 20:01 - 2014-05-04 09:54 - 00000000 ____D () C:\Program Files\MKVToolNix
2014-12-13 19:56 - 2014-03-29 09:51 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-13 15:11 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-12 22:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\SysWOW64\sk-SK
2014-12-12 22:17 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sk-SK
Some content of TEMP:
====================
C:\Users\f4r0\AppData\Local\Temp\InstHelper.exe
C:\Users\f4r0\AppData\Local\Temp\Quarantine.exe
C:\Users\f4r0\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 13:20
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
Drive c: (System) (Fixed) (Total:99.03 GB) (Free:47.45 GB) NTFS
Drive d: (Games) (Fixed) (Total:290.7 GB) (Free:20.73 GB) NTFS
Drive e: (Store) (Fixed) (Total:541.67 GB) (Free:111.53 GB) NTFS
Drive g: (Worms Clan Wars) (CDROM) (Total:1.35 GB) (Free:0 GB) CDFS
Available physical RAM: 5831.72 MB
Total physical RAM: 8189.55 MB
Percentage of memory in use: 28%
==================== MBR and Partition Table ==================
Disk: 0 (Size: 931.5 GB) (Disk ID: 0004672C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=99 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=290.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=541.7 GB) - (Type=OF Extended)
==================== Scheduled Tasks (whitelisted) ==================
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:DEDEE4A9
==================== Security Center ==================
AV: ESET Smart Security 8.0 (Enabled - Up to date) {19259FAE-8396-A113-46DB-15B0E7DFA289}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 8.0 (Enabled - Up to date) {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: ESET Personálny Firewall (Enabled) {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\f4r0\Desktop" je 656 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
- Přílohy
-
- Addition.rar
- (8.25 KiB) Staženo 50 x
Re: dvojity ´´ ˇˇ
- Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
- ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
- znovu spustte FRST a kliknete na Fix
- po restartu na Vas vyskoci fixlog (pripadne bude ulozen na Plose), jehoz obsah mi vlozte do pristi odpovedi
Kód: Vybrat vše
Start CloseProcesses: HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd) HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\RunOnce: [Adobe Speed Launcher] => 1420885501 HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {0d9a749c-899d-11e3-b382-000272a6c7a3} - G:\setup.exe HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {d2ce7013-abaa-11e3-bca9-000272a6c7a3} - G:\NokiaPCIA_Autorun.exe HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {e443e277-4ada-11e4-9f50-1c6f65893f0a} - I:\LG_PC_Programs.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File U3 DfSdkS; No ImagePath 2015-01-10 13:06 - 2015-01-10 13:06 - 00014655 _____ () C:\Users\f4r0\Desktop\FRST.txt 2015-01-10 13:03 - 2015-01-10 13:04 - 00112640 _____ (forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe 2015-01-10 11:16 - 2015-01-10 11:23 - 00000000 ____D () C:\AdwCleaner 2015-01-09 14:39 - 2015-01-09 14:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP 2015-01-09 13:57 - 2015-01-09 14:13 - 00000000 ____D () C:\Program Files\trend micro 2015-01-09 11:47 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\SysWOW64\sh4native.exe 2014-12-14 15:30 - 2015-01-09 14:39 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter 2015-01-08 16:51 - 2014-03-14 14:08 - 00000000 ____D () C:\Windows\AutoKMS AlternateDataStreams: C:\ProgramData\TEMP:DEDEE4A9 Task: {4B7B2C79-414F-473B-B7EB-51FD05E22AFF} - System32\Tasks\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C} => pcalua.exe -a C:\Users\f4r0\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=obw C:\Users\f4r0\AppData\Roaming\omiga-plus Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Hosts: EmptyTemp: End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-01-2015
Ran by f4r0 at 2015-01-10 19:16:37 Run:1
Running from C:\Users\f4r0\Desktop
Loaded Profile: f4r0 (Available profiles: f4r0)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\RunOnce: [Adobe Speed Launcher] => 1420885501
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {0d9a749c-899d-11e3-b382-000272a6c7a3} - G:\setup.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {d2ce7013-abaa-11e3-bca9-000272a6c7a3} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {e443e277-4ada-11e4-9f50-1c6f65893f0a} - I:\LG_PC_Programs.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File
U3 DfSdkS; No ImagePath
2015-01-10 13:06 - 2015-01-10 13:06 - 00014655 _____ () C:\Users\f4r0\Desktop\FRST.txt
2015-01-10 13:03 - 2015-01-10 13:04 - 00112640 _____ (forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
2015-01-10 11:16 - 2015-01-10 11:23 - 00000000 ____D () C:\AdwCleaner
2015-01-09 14:39 - 2015-01-09 14:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2015-01-09 13:57 - 2015-01-09 14:13 - 00000000 ____D () C:\Program Files\trend micro
2015-01-09 11:47 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\SysWOW64\sh4native.exe
2014-12-14 15:30 - 2015-01-09 14:39 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2015-01-08 16:51 - 2014-03-14 14:08 - 00000000 ____D () C:\Windows\AutoKMS
AlternateDataStreams: C:\ProgramData\TEMP:DEDEE4A9
Task: {4B7B2C79-414F-473B-B7EB-51FD05E22AFF} - System32\Tasks\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C} => pcalua.exe -a C:\Users\f4r0\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=obw
C:\Users\f4r0\AppData\Roaming\omiga-plus
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Adobe Speed Launcher => value deleted successfully.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d9a749c-899d-11e3-b382-000272a6c7a3}" => Key deleted successfully.
HKCR\CLSID\{0d9a749c-899d-11e3-b382-000272a6c7a3} => Key not found.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d2ce7013-abaa-11e3-bca9-000272a6c7a3}" => Key deleted successfully.
HKCR\CLSID\{d2ce7013-abaa-11e3-bca9-000272a6c7a3} => Key not found.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e443e277-4ada-11e4-9f50-1c6f65893f0a}" => Key deleted successfully.
HKCR\CLSID\{e443e277-4ada-11e4-9f50-1c6f65893f0a} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.2" => Key deleted successfully.
DfSdkS => Service deleted successfully.
C:\Users\f4r0\Desktop\FRST.txt => Moved successfully.
C:\Users\f4r0\Desktop\FRSTLauncher.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Windows\SysWOW64\sh4native.exe => Moved successfully.
C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter => Moved successfully.
C:\Windows\AutoKMS => Moved successfully.
C:\ProgramData\TEMP => ":DEDEE4A9" ADS removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4B7B2C79-414F-473B-B7EB-51FD05E22AFF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B7B2C79-414F-473B-B7EB-51FD05E22AFF}" => Key deleted successfully.
C:\Windows\System32\Tasks\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C}" => Key deleted successfully.
"C:\Users\f4r0\AppData\Roaming\omiga-plus" => File/Directory not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 164.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog 19:16:41 ====
Ran by f4r0 at 2015-01-10 19:16:37 Run:1
Running from C:\Users\f4r0\Desktop
Loaded Profile: f4r0 (Available profiles: f4r0)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
Start
CloseProcesses:
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3675352 2013-10-28] (Disc Soft Ltd)
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\RunOnce: [Adobe Speed Launcher] => 1420885501
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {0d9a749c-899d-11e3-b382-000272a6c7a3} - G:\setup.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {d2ce7013-abaa-11e3-bca9-000272a6c7a3} - G:\NokiaPCIA_Autorun.exe
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\...\MountPoints2: {e443e277-4ada-11e4-9f50-1c6f65893f0a} - I:\LG_PC_Programs.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll No File
U3 DfSdkS; No ImagePath
2015-01-10 13:06 - 2015-01-10 13:06 - 00014655 _____ () C:\Users\f4r0\Desktop\FRST.txt
2015-01-10 13:03 - 2015-01-10 13:04 - 00112640 _____ (forum.viry.cz) C:\Users\f4r0\Desktop\FRSTLauncher.exe
2015-01-10 11:16 - 2015-01-10 11:23 - 00000000 ____D () C:\AdwCleaner
2015-01-09 14:39 - 2015-01-09 14:39 - 00000000 ____D () C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP
2015-01-09 13:57 - 2015-01-09 14:13 - 00000000 ____D () C:\Program Files\trend micro
2015-01-09 11:47 - 2010-05-13 17:34 - 00014232 _____ () C:\Windows\SysWOW64\sh4native.exe
2014-12-14 15:30 - 2015-01-09 14:39 - 00000000 ____D () C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2015-01-08 16:51 - 2014-03-14 14:08 - 00000000 ____D () C:\Windows\AutoKMS
AlternateDataStreams: C:\ProgramData\TEMP:DEDEE4A9
Task: {4B7B2C79-414F-473B-B7EB-51FD05E22AFF} - System32\Tasks\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C} => pcalua.exe -a C:\Users\f4r0\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=obw
C:\Users\f4r0\AppData\Roaming\omiga-plus
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Hosts:
EmptyTemp:
End
*****************
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Adobe ARM => value deleted successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value deleted successfully.
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value deleted successfully.
HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Adobe Speed Launcher => value deleted successfully.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d9a749c-899d-11e3-b382-000272a6c7a3}" => Key deleted successfully.
HKCR\CLSID\{0d9a749c-899d-11e3-b382-000272a6c7a3} => Key not found.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d2ce7013-abaa-11e3-bca9-000272a6c7a3}" => Key deleted successfully.
HKCR\CLSID\{d2ce7013-abaa-11e3-bca9-000272a6c7a3} => Key not found.
"HKU\S-1-5-21-2804201978-2127736804-1701630455-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e443e277-4ada-11e4-9f50-1c6f65893f0a}" => Key deleted successfully.
HKCR\CLSID\{e443e277-4ada-11e4-9f50-1c6f65893f0a} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@esn/npbattlelog,version=2.3.2" => Key deleted successfully.
DfSdkS => Service deleted successfully.
C:\Users\f4r0\Desktop\FRST.txt => Moved successfully.
C:\Users\f4r0\Desktop\FRSTLauncher.exe => Moved successfully.
C:\AdwCleaner => Moved successfully.
C:\Windows\AF54923662584AC6A0435B5B89C6EB61.TMP => Moved successfully.
C:\Program Files\trend micro => Moved successfully.
C:\Windows\SysWOW64\sh4native.exe => Moved successfully.
C:\Users\f4r0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter => Moved successfully.
C:\Windows\AutoKMS => Moved successfully.
C:\ProgramData\TEMP => ":DEDEE4A9" ADS removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4B7B2C79-414F-473B-B7EB-51FD05E22AFF}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4B7B2C79-414F-473B-B7EB-51FD05E22AFF}" => Key deleted successfully.
C:\Windows\System32\Tasks\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C} => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C806AE6A-43ED-4282-935B-5A4CB7CFF13C}" => Key deleted successfully.
"C:\Users\f4r0\AppData\Roaming\omiga-plus" => File/Directory not found.
C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cf1da82a69828e.job => Moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => Moved successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 164.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog 19:16:41 ====
Re: dvojity ´´ ˇˇ
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
Diakritika je OK a aj vstko ostatne. velka vdaka za vas cas a smekam 
Re: dvojity ´´ ˇˇ
Oukej, to rad slysim, takze jeste uklidime.
- Stahnete a spustte DelFix - https://toolslib.net/downloads/viewdownload/2-delfix/
- Oznacte jen moznost "Remove disinfection tools"
- kliknete na Run
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.
Re: dvojity ´´ ˇˇ
tento log uz asi nebol nutny, ale tak pre istotu 
a este raz velka vdaka
a este raz velka vdaka
Kód: Vybrat vše
# DelFix v10.8 - Logfile created 10/01/2015 at 19:55:17
# Updated 29/07/2014 by Xplode
# Username : f4r0 - F4R0-PC
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
~ Removing disinfection tools ...
Deleted : C:\FRST
Deleted : C:\Users\f4r0\Desktop\Fixlog.txt
Deleted : C:\Users\f4r0\Desktop\FRST64.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
########## - EOF - ##########

Přispějete na provoz fóra?