Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2014
Ran by Martin (administrator) on MARTIN-PC on 26-01-2014 22:51:13
Running from G:\
Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Czech
Internet Explorer Version 9
Boot Mode: Safe Mode (minimal)
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) ===================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [PLFSet] - C:\Windows\PLFSet.dll [45056 2007-12-14] ( )
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [8534560 2008-03-11] (NVIDIA Corporation)
HKLM\...\Run: [SynTPStart] - C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2008-01-24] (Synaptics, Inc.)
HKLM\...\Run: [eDataSecurity Loader] - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [518656 2008-02-25] (Egis Incorporated)
HKLM\...\Run: [eAudio] - C:\Acer\Empowering Technology\eAudio\eAudio.exe [1286144 2007-10-10] (CyberLink)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [4702208 2008-01-24] (Realtek Semiconductor)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\QtZgAcer.EXE [707080 2008-01-02] (Dritek System Inc.)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [641704 2012-11-16] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1778640 2014-01-13] (APN)
HKLM\...\Run: [VNT] - C:\Program Files\VNT\vntldr.exe [202192 2014-01-13] (APN LLC.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [ArcSoft Connection Service] - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKCU\...\Run: [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2009-04-11] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [AcerScrSav] - C:\Windows\Acer\run_NB.exe [ 2007-08-21] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.seznam.cz/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://www.dalesearch.com/?q={searchTer ... 0&tsp=5009
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
http://www.dalesearch.com/?q={searchTer ... 0&tsp=5009
BHO: Ask Toolbar - {5054562D-5247-006A-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\PTV-RG\Passport.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (HiTRUST)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Toolbar: HKLM - Ask Toolbar - {5054562D-5247-006A-76A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\PTV-RG\Passport.dll (APN LLC.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 02 %SystemRoot%\system32\napinsp.dll [50176] (Společnost Microsoft)
FireFox:
========
FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default
FF NewTab: hxxp://
www.dalesearch.com/?babsrc=NT_ss&mntrId ... 0&tsp=5009
FF DefaultSearchEngine: DaleSearch
FF SelectedSearchEngine: DaleSearch
FF Homepage:
www.seznam.cz
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=0.9.9 - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default\searchplugins\babylon.xml
FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default\searchplugins\bingp.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\jyxo-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF Extension: Ask Toolbar - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default\Extensions\
toolbar_PTV-RG@apn.ask.com.xpi [2013-08-29]
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2012-04-09]
FF Extension: DownThemAll! - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\cgkyifto.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2011-08-22]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-24]
FF Extension: Skype Click to Call - C:\Program Files\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-24]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
Chrome:
=======
CHR HomePage: hxxp://
www.seznam.cz/
CHR Plugin: (Shockwave Flash) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\32.0.1700.76\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll (Sun Microsystems, Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (VLC Multimedia Plug-in) - C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Extension: (Ask Toolbar) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaahnibljmklpljnbpgfobmfpfhplch [2013-10-01]
CHR Extension: (Skype Click to Call) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2013-08-13]
CHR Extension: (Peněženka Google) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-27]
CHR HKLM\...\Chrome\Extension: [aaaahnibljmklpljnbpgfobmfpfhplch] - C:\ProgramData\AskPartnerNetwork\Toolbar\PTV-RG\CRX\ToolbarCR.crx [2014-01-13]
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-05-14]
CHR StartMenuInternet: Google Chrome - C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
S2 ACDaemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-01-13] (APN LLC.)
S3 DAUpdaterSvc; D:\Games\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare)
S2 eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe [491008 2008-02-25] (Egis Incorporated)
S2 eLockService; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [24576 2007-10-01] (Acer Inc.)
S2 eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [131072 2007-12-20] (Acer Inc.)
S2 eRecoveryService; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [57344 2007-09-10] (Acer Inc.)
S2 eSettingsService; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [24576 2007-12-19] ()
S2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-11-27] ()
S2 MsgPlusService; C:\Program Files\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe [128000 2013-05-07] (Yuna Software)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
S2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [233472 2007-09-28] (Acer Inc.)
S3 Sony Ericsson PCCompanion; C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCService.exe [155344 2011-06-29] (Avanquest Software)
S2 WMIService; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [167936 2007-09-20] (acer)
S3 8799CE71; C:\Windows\system32\8799CE71.exe [x]
==================== Drivers (Whitelisted) ====================
R3 Afc; C:\Windows\System32\drivers\Afc.sys [18688 2006-11-10] (Arcsoft, Inc.)
S3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdLH3.sys [83984 2012-02-23] (Advanced Micro Devices)
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [281760 2011-02-04] ()
S3 ENTECH; C:\Windows\system32\DRIVERS\ENTECH.sys [27672 2007-08-20] (EnTech Taiwan)
R0 FltMgr; C:\Windows\System32\drivers\fltmgr.sys [190424 2009-04-11] (Společnost Microsoft)
S2 int15; C:\Acer\Empowering Technology\eRecovery\int15.sys [15392 2007-07-03] (Acer, Inc.)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [145664 2013-12-24] (ITE )
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [25888 2011-02-04] ()
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
S3 MsgPlusDriver; C:\Windows\System32\DRIVERS\MsgPlusDriver.sys [118096 2013-05-07] (Yune Software)
R3 Ntfs; C:\Windows\System32\Drivers\Ntfs.sys [1082232 2013-03-03] (Společnost Microsoft)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation)
S3 s1039mdm; C:\Windows\System32\DRIVERS\s1039mdm.sys [124016 2009-11-19] (MCCI Corporation)
S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1729152 2007-12-14] ()
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2008-01-24] (Winbond Electronics Corporation)
S3 ALSysIO; \??\C:\Users\Martin\AppData\Local\Temp\ALSysIO.sys [x]
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Martin\AppData\Local\Temp\catchme.sys [x]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 massfilter; system32\drivers\massfilter.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S4 sptd; System32\Drivers\sptd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-26 22:14 - 2014-01-26 22:14 - 00000000 ____D C:\Users\Martin\Desktop\FRST-OlderVersion
2014-01-26 22:11 - 2014-01-26 22:11 - 00522360 _____ (Duplex Secure Ltd.) C:\Users\Martin\Desktop\SPTDinst-v186-x86.exe
2014-01-26 21:46 - 2014-01-26 21:46 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps
2014-01-26 17:26 - 2014-01-26 17:26 - 00098656 _____ C:\Users\Martin\Desktop\Report.txt
2014-01-26 17:15 - 2014-01-26 17:15 - 00035712 _____ C:\Windows\system32\Drivers\BlackBox.sys
2014-01-26 17:13 - 2014-01-26 17:13 - 00130803 _____ C:\Users\Martin\Desktop\RKUnhookerLE.zip
2014-01-26 17:13 - 2011-02-26 16:07 - 00139264 _____ () C:\Users\Martin\Desktop\RKUnhookerLE.EXE
2014-01-26 17:11 - 2014-01-26 17:11 - 00002081 _____ C:\Users\Martin\Desktop\aswMBR.txt
2014-01-26 17:11 - 2014-01-26 17:11 - 00000512 _____ C:\Users\Martin\Desktop\MBR.dat
2014-01-26 17:07 - 2014-01-26 17:07 - 04745728 _____ (AVAST Software) C:\Users\Martin\Desktop\aswmbr.exe
2014-01-26 00:55 - 2012-08-04 03:48 - 98077435 _____ (Igor Pavlov) C:\Users\Martin\Desktop\OTLPEStd.exe
2014-01-25 22:59 - 2013-12-12 10:32 - 728086778 _____ C:\Users\Martin\Desktop\Balada-pro-banditu_TV-RIP_zkousec_h264_MP3.mp4
2014-01-24 19:17 - 2014-01-24 19:17 - 00065545 _____ C:\ComboFix.txt
2014-01-24 19:00 - 2014-01-24 19:17 - 00000000 ____D C:\ComboFix
2014-01-24 19:00 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-24 19:00 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-24 19:00 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-24 19:00 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-24 19:00 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-24 19:00 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-24 19:00 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-24 19:00 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-24 18:58 - 2014-01-24 19:17 - 00000000 ____D C:\Qoobox
2014-01-24 18:56 - 2014-01-24 19:16 - 00000000 ____D C:\Windows\erdnt
2014-01-24 18:54 - 2014-01-24 18:55 - 05175240 ____R (Swearware) C:\Users\Martin\Desktop\ComboFix.exe
2014-01-24 18:53 - 2014-01-24 18:53 - 00443264 _____ C:\Users\Martin\Desktop\WeatherBlink.exe
2014-01-24 00:39 - 2014-01-24 00:39 - 00003262 _____ C:\Users\Martin\Desktop\RKreport[0]_S_01242014_003959.txt
2014-01-24 00:36 - 2014-01-24 00:42 - 00000000 ____D C:\Users\Martin\Desktop\RK_Quarantine
2014-01-24 00:36 - 2014-01-24 00:36 - 03809280 _____ C:\Users\Martin\Desktop\RogueKiller.exe
2014-01-24 00:31 - 2014-01-24 00:31 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Desktop\tdsskiller.exe
2014-01-23 21:45 - 2014-01-23 22:04 - 172207440 _____ C:\Users\Martin\Downloads\Teorie-velkeho-tresku-TBBT-S07E02-HDTV.mp4
2014-01-23 21:19 - 2014-01-23 21:39 - 185161290 _____ C:\Users\Martin\Downloads\Teorie.velkeho.tresku.S07E01.The.Hofstadter.Insufficiency.HDTV.XviD-AFG.avi
2014-01-23 17:30 - 2014-01-26 22:49 - 00008532 _____ C:\Windows\PFRO.log
2014-01-22 23:08 - 2014-01-22 23:08 - 00056547 _____ C:\Users\Martin\Desktop\OTL.zip
2014-01-22 23:07 - 2014-01-22 23:07 - 00012604 _____ C:\Users\Martin\Desktop\Extras.zip
2014-01-22 22:35 - 2014-01-22 22:35 - 00074558 _____ C:\Users\Martin\Desktop\Extras.Txt
2014-01-22 22:34 - 2014-01-22 22:34 - 00460284 _____ C:\Users\Martin\Desktop\OTL.Txt
2014-01-22 21:55 - 2014-01-22 21:55 - 00000512 _____ C:\PhysicalMBR.bin
2014-01-22 21:48 - 2014-01-22 21:48 - 00602112 _____ (OldTimer Tools) C:\Users\Martin\Desktop\OTL.exe
2014-01-22 21:47 - 2014-01-22 21:47 - 00602112 _____ (OldTimer Tools) C:\Users\Martin\Downloads\OTL.exe
2014-01-22 20:03 - 2014-01-22 20:10 - 00000000 ____D C:\Users\Martin\.smplayer
2014-01-22 20:02 - 2014-01-22 20:02 - 16870192 _____ C:\Users\Martin\Downloads\smplayer-0.8.5-win32.exe
2014-01-22 19:52 - 2014-01-22 20:52 - 00000000 ____D C:\ProgramData\ProgDVB
2014-01-22 19:51 - 2014-01-22 20:52 - 00000000 ____D C:\Program Files\ProgDVB
2014-01-22 19:50 - 2014-01-22 19:51 - 16724376 _____ C:\Users\Martin\Downloads\ProgDVB7.00Std.exe
2014-01-21 23:30 - 2014-01-21 23:30 - 00380416 _____ C:\Users\Martin\Desktop\djd4hw9e.exe
2014-01-21 18:07 - 2014-01-21 18:08 - 00020302 _____ C:\Users\Martin\Desktop\Addition.txt
2014-01-21 18:06 - 2014-01-21 18:08 - 00031319 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-21 18:05 - 2014-01-26 22:14 - 00000000 ____D C:\FRST
2014-01-21 18:04 - 2014-01-26 22:14 - 01222656 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-21 17:58 - 2014-01-21 17:59 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe
2014-01-21 17:56 - 2014-01-21 17:56 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409(2).exe
2014-01-21 17:55 - 2014-01-21 17:55 - 00001238 _____ C:\Users\Martin\Documents\cc_20140121_175552.reg
2014-01-21 17:42 - 2014-01-21 17:42 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409(1).exe
2014-01-05 16:07 - 2014-01-05 17:30 - 732899328 _____ C:\Users\Martin\Downloads\Moderni-popelka-1_CzDab.avi
2014-01-05 12:19 - 2014-01-05 12:19 - 00001816 _____ C:\Users\Martin\Desktop\TotalMedia 3.5.lnk
2014-01-04 00:10 - 2014-01-04 00:34 - 744680960 _____ C:\Users\Martin\Downloads\Obušku-z-pytle-ven-1955.avi
2013-12-29 00:13 - 2013-12-29 00:13 - 00015974 _____ C:\Users\Martin\Documents\cc_20131229_001300.reg
2013-12-28 23:55 - 2013-12-28 23:56 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409.exe
==================== One Month Modified Files and Folders =======
2014-01-26 22:49 - 2014-01-23 17:30 - 00008532 _____ C:\Windows\PFRO.log
2014-01-26 22:48 - 2010-10-25 14:50 - 00000012 _____ C:\Windows\bthservsdp.dat
2014-01-26 22:48 - 2010-10-25 13:54 - 02068968 _____ C:\Windows\WindowsUpdate.log
2014-01-26 22:48 - 2006-11-02 14:01 - 00032572 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-26 22:48 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-26 22:48 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-26 22:48 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-26 22:42 - 2013-10-11 23:21 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-26 22:42 - 2013-09-11 16:41 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-26 22:39 - 2008-01-21 07:47 - 01540550 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-26 22:24 - 2013-10-09 08:14 - 00000966 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2670110533-408426820-3519810110-1000UA.job
2014-01-26 22:14 - 2014-01-26 22:14 - 00000000 ____D C:\Users\Martin\Desktop\FRST-OlderVersion
2014-01-26 22:14 - 2014-01-21 18:05 - 00000000 ____D C:\FRST
2014-01-26 22:14 - 2014-01-21 18:04 - 01222656 _____ (Farbar) C:\Users\Martin\Desktop\FRST.exe
2014-01-26 22:11 - 2014-01-26 22:11 - 00522360 _____ (Duplex Secure Ltd.) C:\Users\Martin\Desktop\SPTDinst-v186-x86.exe
2014-01-26 21:46 - 2014-01-26 21:46 - 00000000 ____D C:\Users\Martin\AppData\Local\CrashDumps
2014-01-26 21:33 - 2013-10-11 23:21 - 00000940 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-26 17:26 - 2014-01-26 17:26 - 00098656 _____ C:\Users\Martin\Desktop\Report.txt
2014-01-26 17:15 - 2014-01-26 17:15 - 00035712 _____ C:\Windows\system32\Drivers\BlackBox.sys
2014-01-26 17:13 - 2014-01-26 17:13 - 00130803 _____ C:\Users\Martin\Desktop\RKUnhookerLE.zip
2014-01-26 17:11 - 2014-01-26 17:11 - 00002081 _____ C:\Users\Martin\Desktop\aswMBR.txt
2014-01-26 17:11 - 2014-01-26 17:11 - 00000512 _____ C:\Users\Martin\Desktop\MBR.dat
2014-01-26 17:07 - 2014-01-26 17:07 - 04745728 _____ (AVAST Software) C:\Users\Martin\Desktop\aswmbr.exe
2014-01-26 15:00 - 2013-10-09 08:14 - 00000914 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2670110533-408426820-3519810110-1000Core.job
2014-01-26 00:00 - 2010-10-26 19:56 - 00000000 ____D C:\Users\Martin\AppData\Local\PokerStars
2014-01-25 20:13 - 2010-10-25 14:36 - 00184320 _____ C:\Users\Martin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-24 19:17 - 2014-01-24 19:17 - 00065545 _____ C:\ComboFix.txt
2014-01-24 19:17 - 2014-01-24 19:00 - 00000000 ____D C:\ComboFix
2014-01-24 19:17 - 2014-01-24 18:58 - 00000000 ____D C:\Qoobox
2014-01-24 19:16 - 2014-01-24 18:56 - 00000000 ____D C:\Windows\erdnt
2014-01-24 19:15 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini
2014-01-24 18:55 - 2014-01-24 18:54 - 05175240 ____R (Swearware) C:\Users\Martin\Desktop\ComboFix.exe
2014-01-24 18:53 - 2014-01-24 18:53 - 00443264 _____ C:\Users\Martin\Desktop\WeatherBlink.exe
2014-01-24 00:42 - 2014-01-24 00:36 - 00000000 ____D C:\Users\Martin\Desktop\RK_Quarantine
2014-01-24 00:39 - 2014-01-24 00:39 - 00003262 _____ C:\Users\Martin\Desktop\RKreport[0]_S_01242014_003959.txt
2014-01-24 00:36 - 2014-01-24 00:36 - 03809280 _____ C:\Users\Martin\Desktop\RogueKiller.exe
2014-01-24 00:31 - 2014-01-24 00:31 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Martin\Desktop\tdsskiller.exe
2014-01-23 22:04 - 2014-01-23 21:45 - 172207440 _____ C:\Users\Martin\Downloads\Teorie-velkeho-tresku-TBBT-S07E02-HDTV.mp4
2014-01-23 21:39 - 2014-01-23 21:19 - 185161290 _____ C:\Users\Martin\Downloads\Teorie.velkeho.tresku.S07E01.The.Hofstadter.Insufficiency.HDTV.XviD-AFG.avi
2014-01-22 23:08 - 2014-01-22 23:08 - 00056547 _____ C:\Users\Martin\Desktop\OTL.zip
2014-01-22 23:07 - 2014-01-22 23:07 - 00012604 _____ C:\Users\Martin\Desktop\Extras.zip
2014-01-22 22:35 - 2014-01-22 22:35 - 00074558 _____ C:\Users\Martin\Desktop\Extras.Txt
2014-01-22 22:34 - 2014-01-22 22:34 - 00460284 _____ C:\Users\Martin\Desktop\OTL.Txt
2014-01-22 21:55 - 2014-01-22 21:55 - 00000512 _____ C:\PhysicalMBR.bin
2014-01-22 21:48 - 2014-01-22 21:48 - 00602112 _____ (OldTimer Tools) C:\Users\Martin\Desktop\OTL.exe
2014-01-22 21:47 - 2014-01-22 21:47 - 00602112 _____ (OldTimer Tools) C:\Users\Martin\Downloads\OTL.exe
2014-01-22 20:52 - 2014-01-22 19:52 - 00000000 ____D C:\ProgramData\ProgDVB
2014-01-22 20:52 - 2014-01-22 19:51 - 00000000 ____D C:\Program Files\ProgDVB
2014-01-22 20:52 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET
2014-01-22 20:49 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2014-01-22 20:10 - 2014-01-22 20:03 - 00000000 ____D C:\Users\Martin\.smplayer
2014-01-22 20:03 - 2010-10-25 14:16 - 00000000 ____D C:\Users\Martin
2014-01-22 20:02 - 2014-01-22 20:02 - 16870192 _____ C:\Users\Martin\Downloads\smplayer-0.8.5-win32.exe
2014-01-22 19:51 - 2014-01-22 19:50 - 16724376 _____ C:\Users\Martin\Downloads\ProgDVB7.00Std.exe
2014-01-21 23:30 - 2014-01-21 23:30 - 00380416 _____ C:\Users\Martin\Desktop\djd4hw9e.exe
2014-01-21 18:08 - 2014-01-21 18:07 - 00020302 _____ C:\Users\Martin\Desktop\Addition.txt
2014-01-21 18:08 - 2014-01-21 18:06 - 00031319 _____ C:\Users\Martin\Desktop\FRST.txt
2014-01-21 17:59 - 2014-01-21 17:58 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe
2014-01-21 17:59 - 2011-06-18 19:31 - 00000000 ____D C:\Program Files\Defraggler
2014-01-21 17:59 - 2010-10-25 19:43 - 00000000 ___RD C:\Users\Martin\Desktop\Programy
2014-01-21 17:56 - 2014-01-21 17:56 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409(2).exe
2014-01-21 17:55 - 2014-01-21 17:55 - 00001238 _____ C:\Users\Martin\Documents\cc_20140121_175552.reg
2014-01-21 17:42 - 2014-01-21 17:42 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409(1).exe
2014-01-19 08:32 - 2010-10-25 16:11 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-18 12:01 - 2008-04-22 02:34 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-18 11:58 - 2013-08-17 18:46 - 00000000 ____D C:\Windows\system32\MRT
2014-01-18 11:55 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-16 01:15 - 2013-11-09 21:28 - 00000000 ____D C:\Users\Martin\AppData\Local\VNT
2014-01-16 01:14 - 2013-11-09 21:28 - 00000000 ____D C:\Program Files\VNT
2014-01-07 23:46 - 2013-11-18 22:11 - 00000000 ____D C:\Users\Martin\Desktop\nevim
2014-01-05 17:30 - 2014-01-05 16:07 - 732899328 _____ C:\Users\Martin\Downloads\Moderni-popelka-1_CzDab.avi
2014-01-05 12:19 - 2014-01-05 12:19 - 00001816 _____ C:\Users\Martin\Desktop\TotalMedia 3.5.lnk
2014-01-04 00:34 - 2014-01-04 00:10 - 744680960 _____ C:\Users\Martin\Downloads\Obušku-z-pytle-ven-1955.avi
2013-12-29 00:13 - 2013-12-29 00:13 - 00015974 _____ C:\Users\Martin\Documents\cc_20131229_001300.reg
2013-12-29 00:04 - 2012-05-05 23:35 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-28 23:56 - 2013-12-28 23:55 - 04645232 _____ (Piriform Ltd) C:\Users\Martin\Downloads\ccsetup409.exe
2013-12-28 23:48 - 2011-10-13 16:30 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-12-28 23:48 - 2008-04-22 02:17 - 00000000 ____D C:\ProgramData\Adobe
2013-12-28 23:47 - 2010-10-25 16:32 - 00000000 ____D C:\Program Files\Adobe
2013-12-28 23:43 - 2011-01-27 18:58 - 00000000 ____D C:\Users\Martin\Downloads\Programy
2013-12-28 00:04 - 2013-12-23 11:56 - 00000000 ____D C:\Users\Martin\Downloads\Evolve
2013-12-27 20:08 - 2012-12-23 13:41 - 00000000 ____D C:\Users\Martin\AppData\Roaming\dvdcss
2013-12-27 00:51 - 2013-12-24 19:48 - 00000000 ____D C:\ProgramData\ArcSoft
2013-12-27 00:51 - 2008-04-22 01:42 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
Files to move or delete:
====================
C:\Users\Martin\AppData\Roaming\desktop.ini
Some content of TEMP:
====================
C:\Users\Martin\AppData\Local\temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-26 22:48
==================== End Of Log ============================