ok tady je
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-12-2015
Ran by Ostatní (administrator) on HONZA-PC (23-12-2015 09:41:34)
Running from C:\Users\Ostatní\Desktop
Loaded Profiles: Ostatní (Available Profiles: Ostatní & Víťa)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Sysinternals process Explorer) C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Realtek) C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtlService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtWLan.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files\LuckyBrowse\app\LuckyBrowse.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 02 C:\Windows\system32\napinsp.dll [50176 2008-01-19] (Společnost Microsoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.33.5 192.168.33.1
Tcpip\..\Interfaces\{3583EDB0-357F-44CC-8D98-E5A2263774DB}: [DhcpNameServer] 192.168.1.254 192.168.33.5 192.168.33.1
Tcpip\..\Interfaces\{7FFB90EE-7754-437C-8334-58FB9162B98E}: [DhcpNameServer] 192.168.1.254 192.168.33.5 192.168.33.1
Tcpip\..\Interfaces\{C9A22C2B-28F5-47D3-9248-6DD7D5E00980}: [DhcpNameServer] 192.168.1.254 192.168.33.5 192.168.33.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1941701972-1158936334-3354527605-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1941701972-1158936334-3354527605-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-1941701972-1158936334-3354527605-1001 -> {0AF36D7C-9BD1-48CB-BAB9-0A781EC27AE2} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=IE_5
SearchScopes: HKU\S-1-5-21-1941701972-1158936334-3354527605-1001 -> {6edb49f6-9ff1-48ab-aefd-8bd004cd0f0c} URL = hxxp://
www.firmy.cz/phr/{searchTerms}?sourceid=IE_5
SearchScopes: HKU\S-1-5-21-1941701972-1158936334-3354527605-1001 -> {b543dec2-2ad2-48de-ba17-25fd66da295c} URL = hxxp://
www.mapy.cz/?query={searchTerms}&sourceid=IE_5
SearchScopes: HKU\S-1-5-21-1941701972-1158936334-3354527605-1001 -> {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL = hxxp://houmpage.com/search/?src=ds&q={searchTerms}&ssid=1450799794&a=1024151&uuid=c96a3c6d-52a0-4533-8380-5a68cc7e56ed
SearchScopes: HKU\S-1-5-21-1941701972-1158936334-3354527605-1001 -> {e4d49ec2-c2a5-46d1-b837-33c0aff3946c} URL = hxxp://
www.zbozi.cz/?q={searchTerms}&r=campmoz&sourceid=IE_5
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre6\bin\ssv.dll [2012-09-22] (Sun Microsystems, Inc.)
BHO: Discover Treasure -> {bfa55139-82af-4663-a19b-e135dac8d043} -> C:\Program Files\Discover Treasure\Extensions\bfa55139-82af-4663-a19b-e135dac8d043.dll => No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-09-22] (Sun Microsystems, Inc.)
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://
www.yoursearching.com/?type=sc&ts=14508 ... X973QFD53S
FireFox:
========
FF ProfilePath: C:\Users\Ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\qshf91mt.default
FF Homepage: hxxp://houmpage.com/?src=hp&ssid=1450799794&a=1024151&uuid=c96a3c6d-52a0-4533-8380-5a68cc7e56ed
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-10] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll [2008-08-06] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_35 -> C:\Windows\system32\npdeployJava1.dll [2012-09-22] (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll [2012-09-22] (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np32dsw.dll [2008-08-06] (Adobe Systems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2012-07-27] (Adobe Systems Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Ostatní\AppData\Roaming\Mozilla\Firefox\Profiles\qshf91mt.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2012-11-25] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2012-09-22] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-12] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://
www.google.cz/
CHR StartupUrls: Default -> "hxxp://
www.google.cz/"
CHR DefaultSearchURL: Default -> hxxp://yoursearching.com/web?type=ds&ts=1450800478&z=df7c2b64de0164e41ef7725g1zcw0e4mft3tfbeo9g&from=exp1&uid=TOSHIBAXMK1237GSX_973QFD53SXX973QFD53S&q={searchTerms}
CHR DefaultSearchKeyword: Default -> yoursearching
CHR Profile: C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Dokumenty Google) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-09]
CHR Extension: (Disk Google) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-27]
CHR Extension: (YouTube) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-19]
CHR Extension: (Vyhledávání Google) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dokumenty Google offline) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-11]
CHR Extension: (Gmail) - C:\Users\Ostatní\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-24]
CHR Extension: (Balance Component) - C:\Users\Ostatní\AppData\Local\Balance Component\Component [2015-12-23]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 CFSvcs; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2006-11-14] (TOSHIBA CORPORATION) [File not signed]
S3 NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [266240 2007-01-15] (Nero AG) [File not signed]
R2 Realtek87B; C:\Program Files\Realtek\RTL8187B Wireless LAN Utility\RtlService.exe [40960 2009-12-07] (Realtek) [File not signed]
R2 TNaviSrv; C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [77824 2007-07-26] (TOSHIBA Corporation) [File not signed]
R2 TODDSrv; C:\Windows\system32\TODDSrv.exe [114688 2006-05-25] (TOSHIBA Corporation) [File not signed]
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-19] (Microsoft Corporation)
R2 WindowsMangerProtect; C:\ProgramData\Tmp0x0x\ProtectWindowsManager.exe [338432 2015-12-22] (Sysinternals process Explorer) [File not signed] <==== ATTENTION
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-10] (Společnost Microsoft)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2015-12-19] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATKACPI.sys [7680 2006-12-14] (ATK0100)
R3 Ntfs; C:\Windows\system32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
R3 RTL8023xp; C:\Windows\System32\DRIVERS\Rtnicxp.sys [50688 2007-07-13] (Realtek Semiconductor Corporation ) [File not signed]
R3 RTL8187B; C:\Windows\System32\DRIVERS\RTL8187B.sys [347648 2009-06-10] (Realtek Semiconductor Corporation )
R0 sfvfs02; C:\Windows\System32\drivers\sfvfs02.sys [83320 2007-02-08] (Protection Technology (StarForce))
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [715248 2012-12-20] () [File not signed]
U3 aahdc176; C:\Windows\system32\Drivers\aahdc176.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero byte File/Folder)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-19] (Microsoft Corporation)
S3 athur; system32\DRIVERS\athur.sys [X]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S0 TVALZ; system32\DRIVERS\TVALZ_O.SYS [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-23 09:41 - 2015-12-23 09:42 - 00012874 _____ C:\Users\Ostatní\Desktop\FRST.txt
2015-12-23 09:40 - 2015-12-23 09:41 - 00000000 ___DC C:\FRST
2015-12-22 21:36 - 2015-12-22 21:36 - 01721344 _____ (Farbar) C:\Users\Ostatní\Desktop\FRST.exe
2015-12-22 17:11 - 2015-12-22 17:11 - 00000000 ____D C:\Users\Ostatní\AppData\Roaming\SimpleFiles
2015-12-22 17:08 - 2015-12-22 17:15 - 00000000 ____D C:\Users\Ostatní\AppData\Roaming\yoursearching
2015-12-22 17:08 - 2015-12-22 17:08 - 00000000 ____D C:\ProgramData\Tmp0x0x
2015-12-22 17:08 - 2015-12-22 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\LuckyBrowse
2015-12-22 17:08 - 2015-12-22 17:08 - 00000000 ____D C:\ProgramData\LuckyBrowse
2015-12-22 17:08 - 2015-12-22 17:08 - 00000000 ____D C:\Program Files\LuckyBrowse
2015-12-22 17:07 - 2015-12-22 17:07 - 00000000 ____D C:\Users\Ostatní\AppData\Local\Balance Component
2015-12-22 14:25 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2015-12-22 14:25 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2015-12-22 14:25 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-12-22 14:25 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-12-22 14:25 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-12-22 14:25 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2015-12-22 14:25 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2015-12-22 14:25 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2015-12-22 14:23 - 2015-12-22 15:00 - 00000000 ____D C:\Windows\erdnt
2015-12-20 15:25 - 2015-12-22 09:17 - 00000000 ____D C:\Users\Ostatní\AppData\Local\Temp(14)
2015-12-20 15:25 - 2015-12-21 15:56 - 00000000 ____D C:\Users\Víťa\AppData\Local\Temp(25)
2015-12-20 15:25 - 2015-12-20 15:25 - 00000000 ____D C:\Users\Honza\AppData\Local\Temp(5)
2015-12-20 14:59 - 2015-12-22 15:02 - 00000000 ___DC C:\Qoobox
2015-12-19 22:18 - 2015-12-22 09:31 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2015-12-19 22:18 - 2015-12-19 22:18 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2015-12-19 22:18 - 2015-12-19 22:18 - 00000911 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-19 22:18 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-12-19 22:11 - 2015-12-19 22:11 - 00000000 ____D C:\Users\Ostatní\AppData\Roaming\Malwarebytes
2015-12-19 22:11 - 2015-12-19 22:11 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-19 19:31 - 2015-12-19 19:57 - 00000000 ___DC C:\AdwCleaner
2015-12-19 19:30 - 2015-12-19 19:30 - 01740288 _____ C:\Users\Ostatní\Downloads\adwcleaner_5.025.exe
2015-12-19 19:20 - 2015-12-19 19:21 - 01496172 _____ C:\Users\Ostatní\Downloads\CrystalDiskInfo5_0_0.zip
2015-12-18 18:14 - 2015-12-22 21:39 - 00000000 ____D C:\Program Files\trend micro
2015-12-18 18:14 - 2015-12-18 18:15 - 00000000 ___DC C:\rsit
2015-12-18 18:13 - 2015-12-18 18:14 - 01107968 _____ C:\Users\Ostatní\Downloads\RSIT.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-23 09:41 - 2006-11-02 12:18 - 00000000 ____D C:\Windows
2015-12-23 09:39 - 2013-12-25 19:14 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-23 09:38 - 2012-09-20 11:24 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-23 09:38 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-23 09:38 - 2006-11-02 13:47 - 00003952 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-23 09:38 - 2006-11-02 13:47 - 00003952 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-23 09:37 - 2006-11-02 14:01 - 00032586 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-23 09:12 - 2013-12-25 19:14 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-23 09:06 - 2012-09-20 11:24 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-12-23 09:06 - 2011-07-09 11:42 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-12-22 17:16 - 2013-12-25 19:18 - 00001976 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-22 17:15 - 2008-08-19 07:53 - 00000954 _____ C:\Users\Ostatní\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-12-22 14:57 - 2006-11-02 11:23 - 00000215 ____C C:\Windows\system.ini
2015-12-22 09:31 - 2013-12-25 19:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-22 09:31 - 2012-12-20 13:46 - 00000000 ____D C:\install
2015-12-22 09:31 - 2012-11-26 18:32 - 00000000 ____D C:\Users\Víťa
2015-12-22 09:31 - 2008-08-19 07:52 - 00000000 ____D C:\Users\Ostatní
2015-12-22 09:31 - 2008-04-21 14:58 - 00000000 ____D C:\Users\Honza
2015-12-22 09:31 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-22 09:31 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration
2015-12-22 09:31 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\inf
2015-12-22 09:31 - 2006-11-02 11:22 - 50593792 _____ C:\Windows\system32\config\software_previous
2015-12-22 09:31 - 2006-11-02 11:22 - 24903680 _____ C:\Windows\system32\config\system_previous
2015-12-22 09:26 - 2006-11-02 11:22 - 56098816 _____ C:\Windows\system32\config\components_previous
2015-12-22 09:26 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2015-12-22 09:17 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2015-12-22 09:17 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\default_previous
2015-12-18 21:04 - 2012-12-17 18:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Return to Castle Wolfenstein
2015-12-18 21:04 - 2012-12-17 18:09 - 00000600 _____ C:\Windows\Rtcw.INI
2015-12-18 21:04 - 2007-09-05 07:49 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-12-18 20:59 - 2012-12-17 17:41 - 00000000 ____D C:\Program Files\EACOM
2015-12-18 20:55 - 2012-12-15 16:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TopCD
==================== Files in the root of some directories =======
2012-12-22 23:44 - 2012-12-22 23:44 - 0000022 ___SH () C:\Users\Ostatní\AppData\Roaming\Windows1569_SettingsRepository.bin
2012-11-21 09:08 - 2012-11-21 09:12 - 0003584 _____ () C:\Users\Ostatní\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-22 23:44 - 2012-12-22 23:44 - 0000000 _____ () C:\Users\Ostatní\AppData\Local\jv16PT_temp.tmp
Files to move or delete:
====================
C:\Users\Víťa\xobglu16.dll
C:\Users\Víťa\xobglu32.dll
Some files in TEMP:
====================
C:\Users\Ostatní\AppData\Local\temp\avgC33F.exe
C:\Users\Ostatní\AppData\Local\temp\BsqYhygSv2.exe
C:\Users\Ostatní\AppData\Local\temp\CQe2OtyyBw.exe
C:\Users\Ostatní\AppData\Local\temp\ksQcMyjfg9.exe
C:\Users\Ostatní\AppData\Local\temp\OKzsGtRg30.exe
C:\Users\Ostatní\AppData\Local\temp\tAfid2cCKd.exe
C:\Users\Ostatní\AppData\Local\temp\tmpE484.tmp.exe
C:\Users\Ostatní\AppData\Local\temp\vY2DQkKcQb.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-23 09:17
==================== End of FRST.txt ============================