Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-09-2013 04
Ran by Radim (administrator) on RADIM-PC on 14-09-2013 16:52:24
Running from C:\Users\Radim\Desktop
Windows 7 Ultimate Service Pack 1 (X86) OS Language: Czech
Internet Explorer Version 10
Boot Mode: Normal
==================== Could not list processes ===============
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Easy-PrintToolBox] - C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [398944 2006-10-17] (CANON INC.)
HKLM\...\Run: [SoundMan] - C:\Windows\SOUNDMAN.EXE [604704 2009-04-14] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PinnacleDriverCheck] - C:\Windows\system32\PSDrvCheck.exe [406016 2004-03-10] ()
HKLM\...\Run: [USBToolTip] - C:\PROGRA~1\Pinnacle\SHARED~1\Programs\USBTip\USBTip.exe [199752 2007-02-20] (Pinnacle Systems GmbH)
HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [979328 2010-08-30] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [3117344 2012-03-07] (ESET)
Startup: C:\Users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Kooperativa - PDF Server.lnk
ShortcutTarget: Kooperativa - PDF Server.lnk -> C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe ()
Startup: C:\Users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lczj2w7d.lnk
ShortcutTarget: lczj2w7d.lnk -> d7w2jzcl.plz,GL300 (No File)
Startup: C:\Users\Radim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk
ShortcutTarget: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk -> C:\Programy\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://seznam.cz/
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programy\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programy\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 10.10.10.1
FireFox:
========
FF ProfilePath: C:\Users\Radim\AppData\Roaming\Mozilla\Firefox\Profiles\1rd4uxuf.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=1.6.0_33 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @Nero.com/KM - C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF Plugin: @real.com/nppl3260;version=6.0.12.69 - C:\Program Files\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.69 - C:\Program Files\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM\...\FireFox\Extensions: [
ntfdsaftsfdfdxx@mozilla.org] - C:\Users\Radim\AppData\Roaming\iPumper\extension_firefox.xpi
FF HKLM\...\Thunderbird\Extensions: [
eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
Chrome:
=======
CHR HomePage: hxxp://isearch.babylon.com/?affID=116632&tt=0113_8&babsrc=HP_ss&mntrId=b891b345000000000000f4ec38c64cbb
CHR RestoreOnStartup: "hxxp://isearch.babylon.com/?affID=116632&tt=0113_8&babsrc=HP_ss&mntrId=b891b345000000000000f4ec38c64cbb"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\23.0.1271.64\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\23.0.1271.64\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\23.0.1271.64\pdf.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Nero Kwik Media Helper) - C:\PROGRA~1\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U33) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.330.3) - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR HKLM\...\Chrome\Extension: [kekfoodhbhpjhjcdecjngamojfhknooc] - C:\Users\Radim\AppData\Roaming\iPumper\extension_chrome.crx
========================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-01] (Akamai Technologies, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [913144 2012-03-07] (ESET)
R2 EPSON_EB_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50ST7.EXE [153600 2009-09-14] (SEIKO EPSON CORPORATION)
R2 EPSON_PM_RPCV4_04; C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RP7.EXE [121856 2009-09-14] (SEIKO EPSON CORPORATION)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106280 2013-09-14] (SurfRight B.V.)
S3 Microsoft Office Groove Audit Service; C:\Programy\Microsoft Office\Office12\GrooveAuditService.exe [64856 2009-02-26] (Microsoft Corporation)
R2 NAUpdate; C:\Program Files\Nero\Update\NASvc.exe [641832 2011-09-23] (Nero AG)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software)
S2 Winmgmt; C:\PROGRA~2\d7w2jzcl.plz [x]
==================== Drivers (Whitelisted) ====================
R3 ALCXWDM; C:\Windows\System32\drivers\RTKVAC.SYS [4172832 2009-06-18] (Realtek Semiconductor Corp.)
R3 ASAPIW2k; C:\Windows\System32\drivers\ASAPIW2k.sys [11264 2004-03-10] (Pinnacle Systems GmbH)
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R1 DumaNT; C:\Windows\System32\DRIVERS\dumant.sys [399700 2002-11-18] (NVIDIA Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [169080 2012-03-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [120152 2012-03-14] (ESET)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [24232 2009-02-17] (Elaborate Bytes AG)
R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [103112 2012-03-14] (ESET)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [90368 2011-02-25] (Huawei Technologies Co., Ltd.)
R3 MarvinBus; C:\Windows\System32\DRIVERS\MarvinBus.sys [171520 2005-09-23] (Pinnacle Systems GmbH)
R1 PCLEPCI; C:\Windows\system32\drivers\pclepci.sys [14165 2004-07-16] (Pinnacle Systems GmbH)
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-14] (NXP Semiconductors)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [436792 2011-07-10] ()
U3 a2u24c9k; C:\Windows\System32\Drivers\a2u24c9k.sys [0 ] (Advanced Micro Devices)
U3 a8l3qoea; C:\Windows\System32\Drivers\a8l3qoea.sys [0 ] (Advanced Micro Devices)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-14 16:51 - 2013-09-14 16:48 - 01083285 _____ (Farbar) C:\Users\Radim\Desktop\FRST.exe
2013-09-14 12:04 - 2013-09-14 12:04 - 00000000 ____D C:\FRST
2013-09-14 11:48 - 2013-09-14 11:48 - 00001897 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2013-09-14 11:48 - 2013-09-14 11:48 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-14 11:48 - 2013-09-14 11:48 - 00000000 ____D C:\Program Files\HitmanPro
2013-09-12 22:45 - 2013-09-14 12:01 - 00000000 _____ C:\ProgramData\lczj2w7d.ctrl
2013-09-12 22:45 - 2013-09-12 23:20 - 95025368 ____T C:\ProgramData\lczj2w7d.pff
2013-09-12 13:59 - 2013-08-10 05:59 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-09-12 13:59 - 2013-08-10 05:59 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-09-12 13:59 - 2013-08-10 05:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-09-12 13:59 - 2013-08-10 05:58 - 14332928 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 13761024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 02876928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 02048000 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-09-12 13:59 - 2013-08-10 05:58 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-09-12 13:59 - 2013-08-10 05:07 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-09-12 13:59 - 2013-08-10 04:17 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-09-12 04:44 - 2013-08-08 03:03 - 02348544 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-09-12 04:44 - 2013-08-05 03:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2013-09-12 04:44 - 2013-07-26 03:55 - 12872704 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2013-09-12 04:44 - 2013-07-26 03:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2013-09-12 04:43 - 2013-08-02 03:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2013-09-12 04:43 - 2013-08-02 03:49 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2013-09-12 04:43 - 2013-08-02 03:49 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 03:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 02:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2013-09-12 04:43 - 2013-08-02 02:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 02:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 02:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2013-09-12 04:43 - 2013-08-02 02:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2013-09-08 11:46 - 2013-09-12 19:07 - 00000210 _____ C:\Users\Radim\Desktop\!0.1!.txt
2013-09-05 22:15 - 2013-09-11 22:15 - 00056832 _____ C:\Users\Radim\Desktop\Plán seminářů - září - september 2013.xls
2013-09-05 22:13 - 2013-09-11 22:14 - 00012775 _____ C:\Users\Radim\Desktop\Plán tréninků 09 2013.xlsx
2013-08-27 00:03 - 2013-09-12 13:49 - 00000252 _____ C:\Users\Radim\Desktop\DNES.txt
2013-08-24 12:46 - 2013-08-24 12:46 - 14012484 _____ C:\Users\Radim\Downloads\SaltLakesDeadSea.themepack
2013-08-24 12:36 - 2013-08-24 12:36 - 22843406 _____ C:\Users\Radim\Downloads\AucklandOneTreeHillIanRushton.themepack
2013-08-24 12:36 - 2013-08-24 12:36 - 15412792 _____ C:\Users\Radim\Downloads\Hawaii.themepack
2013-08-19 14:43 - 2013-08-19 14:43 - 00000140 _____ C:\Users\Radim\Desktop\NÁVOD-ZFP.txt
2013-08-15 08:14 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-15 08:14 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-15 08:14 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-15 08:14 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-15 08:14 - 2013-07-09 06:50 - 00652800 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-15 08:14 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-15 08:14 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-15 08:14 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2013-08-15 08:13 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-15 08:13 - 2013-07-09 06:53 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-15 08:13 - 2013-07-06 07:05 - 01293760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-15 08:12 - 2013-06-15 05:40 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2013-08-15 08:12 - 2013-06-15 05:38 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
==================== One Month Modified Files and Folders =======
2013-09-14 16:48 - 2013-09-14 16:51 - 01083285 _____ (Farbar) C:\Users\Radim\Desktop\FRST.exe
2013-09-14 16:33 - 2010-04-18 23:56 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-14 15:56 - 2013-01-04 14:57 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-14 13:54 - 2009-07-14 06:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-14 13:54 - 2009-07-14 06:34 - 00014224 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-14 13:47 - 2012-01-28 16:56 - 00000000 ____D C:\Program Files\Common Files\Akamai
2013-09-14 13:47 - 2010-04-18 23:56 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-14 13:46 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-14 13:46 - 2009-07-14 06:39 - 00212587 _____ C:\Windows\setupact.log
2013-09-14 13:45 - 2010-04-09 15:50 - 01986530 _____ C:\Windows\WindowsUpdate.log
2013-09-14 13:05 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-09-14 12:04 - 2013-09-14 12:04 - 00000000 ____D C:\FRST
2013-09-14 12:01 - 2013-09-12 22:45 - 00000000 _____ C:\ProgramData\lczj2w7d.ctrl
2013-09-14 11:48 - 2013-09-14 11:48 - 00001897 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2013-09-14 11:48 - 2013-09-14 11:48 - 00000000 ____D C:\ProgramData\HitmanPro
2013-09-14 11:48 - 2013-09-14 11:48 - 00000000 ____D C:\Program Files\HitmanPro
2013-09-14 10:00 - 2010-04-10 12:54 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-09-12 23:20 - 2013-09-12 22:45 - 95025368 ____T C:\ProgramData\lczj2w7d.pff
2013-09-12 22:23 - 2013-08-04 17:45 - 00000719 _____ C:\Users\Radim\Desktop\!0!.txt
2013-09-12 22:21 - 2010-04-10 19:32 - 00000000 ____D C:\Users\Radim\AppData\Roaming\vlc
2013-09-12 21:10 - 2010-04-22 00:58 - 00000000 ____D C:\Users\Radim\AppData\Roaming\dvdcss
2013-09-12 20:59 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET
2013-09-12 20:53 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\system32\FxsTmp
2013-09-12 19:07 - 2013-09-08 11:46 - 00000210 _____ C:\Users\Radim\Desktop\!0.1!.txt
2013-09-12 19:02 - 2010-04-09 16:03 - 01478586 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-12 18:54 - 2009-07-14 06:33 - 00484768 _____ C:\Windows\system32\FNTCACHE.DAT
2013-09-12 13:56 - 2013-07-25 12:36 - 00000000 ____D C:\Windows\system32\MRT
2013-09-12 13:52 - 2010-04-10 19:16 - 76725432 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-09-12 13:49 - 2013-08-27 00:03 - 00000252 _____ C:\Users\Radim\Desktop\DNES.txt
2013-09-12 11:32 - 2013-07-18 22:26 - 00000302 _____ C:\Users\Radim\Desktop\! 1 !.txt
2013-09-12 10:38 - 2013-04-12 11:44 - 00000823 _____ C:\Users\Radim\Desktop\! ! ! ! !.txt
2013-09-11 22:15 - 2013-09-05 22:15 - 00056832 _____ C:\Users\Radim\Desktop\Plán seminářů - září - september 2013.xls
2013-09-11 22:14 - 2013-09-05 22:13 - 00012775 _____ C:\Users\Radim\Desktop\Plán tréninků 09 2013.xlsx
2013-09-11 20:56 - 2013-06-07 23:12 - 00000415 _____ C:\Users\Radim\Desktop\Peníze.txt
2013-09-11 20:56 - 2013-01-04 14:57 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-11 20:56 - 2011-06-01 21:08 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-08 14:26 - 2011-09-18 11:24 - 00000000 ____D C:\Users\Radim\Desktop\Lemmings
2013-09-06 10:13 - 2013-08-06 13:32 - 00000560 _____ C:\Users\Radim\Desktop\D.txt
2013-08-26 19:46 - 2009-07-14 06:53 - 00032628 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-08-24 12:46 - 2013-08-24 12:46 - 14012484 _____ C:\Users\Radim\Downloads\SaltLakesDeadSea.themepack
2013-08-24 12:36 - 2013-08-24 12:36 - 22843406 _____ C:\Users\Radim\Downloads\AucklandOneTreeHillIanRushton.themepack
2013-08-24 12:36 - 2013-08-24 12:36 - 15412792 _____ C:\Users\Radim\Downloads\Hawaii.themepack
2013-08-21 23:19 - 2013-07-11 11:23 - 00000349 _____ C:\Users\Radim\Desktop\!.txt
2013-08-20 23:01 - 2013-04-03 23:30 - 00000259 _____ C:\Users\Radim\Desktop\! !.txt
2013-08-19 14:43 - 2013-08-19 14:43 - 00000140 _____ C:\Users\Radim\Desktop\NÁVOD-ZFP.txt
2013-08-16 20:43 - 2012-12-29 12:06 - 00026112 _____ C:\Users\Radim\Desktop\výměna věcí z auta.xls
2013-08-15 19:58 - 2013-02-11 23:57 - 00020992 _____ C:\Users\Radim\Desktop\Zbylé kontakty.xls
Files to move or delete:
====================
C:\ProgramData\lczj2w7d.ctrl
C:\ProgramData\lczj2w7d.pff
Some content of TEMP:
====================
C:\Users\Radim\AppData\Local\Temp\DivXSetup.exe
C:\Users\Radim\AppData\Local\Temp\fgowwarwqqaphiohrio.bfg
C:\Users\Radim\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Radim\AppData\Local\Temp\FlashPlayerUpdate01.exe
C:\Users\Radim\AppData\Local\Temp\jre-6u20-windows-i586-iftw-rv.exe
C:\Users\Radim\AppData\Local\Temp\jre-6u21-windows-i586-iftw-rv.exe
C:\Users\Radim\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Radim\AppData\Local\Temp\jre-6u26-windows-i586-iftw-rv.exe
C:\Users\Radim\AppData\Local\Temp\jre-6u33-windows-i586-iftw.exe
C:\Users\Radim\AppData\Local\Temp\KoopFlash10FF.exe
C:\Users\Radim\AppData\Local\Temp\KoopFlash10IE.exe
C:\Users\Radim\AppData\Local\Temp\ose00000.exe
C:\Users\Radim\AppData\Local\Temp\RTBK.EXE
C:\Users\Radim\AppData\Local\Temp\Setup.exe
C:\Users\Radim\AppData\Local\Temp\tmpCE53.exe
C:\Users\Radim\AppData\Local\Temp\toolbar2332031.exe
C:\Users\Radim\AppData\Local\Temp\uninstall13719890.exe
C:\Users\Radim\AppData\Local\Temp\uninstall13729984.exe
C:\Users\Radim\AppData\Local\Temp\wervwyuu0.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-14 12:51
==================== End Of Log ============================