Re: podivné chování PC
Napsal: 12 kvě 2014 08:48
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-05-2014 01
Ran by Julie (administrator) on JULINKA on 12-05-2014 09:43:58
Running from C:\Users\Julie\Desktop
Platform: Windows 8.1 Pro (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(GreenVantage LLC) D:\CPUgenie\CPUgenie.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\livecomm.exe
(Ghisler Software GmbH) D:\totalcmd\TOTALCMD.EXE
(forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-10] (AVAST Software)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKU\S-1-5-21-2508871071-1620209755-3458330456-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20924064 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2508871071-1620209755-3458330456-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = seznam.cz
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = seznam.cz
SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {126AD505-4E16-4497-944B-5BA1EAE183D1} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {1758B189-998A-4CB5-9B40-A501776390FD} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {5D2B6519-32E6-4C5E-953C-290AD0F48C4F} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {5D8C45BD-1AB9-4939-9BB9-2ED68696E312} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {5FB9F448-6B35-4D35-88B1-83B65CB9ACD1} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {D6DB4887-D03C-4DF9-B630-E240050E9767} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {E4F8CB08-A423-4110-B799-28B3CE57F032} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {EE815BFD-7521-4D40-907B-4F2D0D824E17} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {F71DDAB7-472A-4B1C-A545-96F12CFEE8FE} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\j8kzt4ak.default-1399798244496
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Julie\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-10] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-05-10] (AVAST Software)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [47160 2008-04-28] (AMD, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-10] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-05-10] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-10] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-05-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-10] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-10] ()
S3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 CPUgenieDriver; D:\CPUgenie\NBFreezer.sys [14960 2010-05-11] (GreenVantage LLC)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [43520 2014-04-23] (Elex do Brasil Participações Ltda)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
S3 winbondcir; C:\Windows\system32\DRIVERS\winbondcir.sys [46592 2007-03-28] (Winbond Electronics Corporation)
S1 iSafeKrnlKit; \??\C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-12 09:43 - 2014-05-12 09:44 - 00012009 _____ () C:\Users\Julie\Desktop\FRST.txt
2014-05-12 09:42 - 2014-05-12 09:43 - 00000000 ____D () C:\FRST
2014-05-12 09:42 - 2014-05-12 09:40 - 00112640 _____ (forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
2014-05-12 09:41 - 2014-05-12 09:39 - 02066944 _____ (Farbar) C:\Users\Julie\Desktop\FRST64.exe
2014-05-11 22:57 - 2014-05-11 22:42 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-11 22:43 - 2014-05-11 23:20 - 00008519 _____ () C:\zoek-results.log
2014-05-11 22:42 - 2014-05-11 22:55 - 00000000 ____D () C:\zoek_backup
2014-05-11 22:42 - 2014-05-11 22:42 - 01285120 _____ () C:\Users\Julie\Desktop\zoek.exe
2014-05-11 16:53 - 2014-05-11 16:53 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 16:48 - 2014-05-11 16:49 - 00000000 ____D () C:\AdwCleaner
2014-05-11 16:47 - 2014-05-11 16:43 - 01316991 _____ () C:\Users\Julie\Desktop\adwcleaner.exe
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\rsit
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\Program Files\trend micro
2014-05-11 14:59 - 2014-05-11 14:59 - 39935131 _____ (Hi-Rez Studios) C:\Users\Julie\Downloads\InstallHiRezGamesEnglish(1).exe
2014-05-11 14:52 - 2014-05-11 15:03 - 00000000 ____D () C:\Users\Julie\Desktop\RK_Quarantine
2014-05-11 14:52 - 2014-05-11 14:52 - 03972608 _____ () C:\Users\Julie\Downloads\RogueKiller(4).exe
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Windows\Options
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-05-11 11:18 - 2014-02-14 03:35 - 03888640 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athwbx.sys
2014-05-11 10:42 - 2014-05-11 23:19 - 00002946 _____ () C:\Windows\PFRO.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setupact.log
2014-05-10 21:42 - 2014-05-10 21:42 - 00001988 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-05-10 21:41 - 2014-05-10 21:41 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-10 21:41 - 2014-05-10 21:41 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-05-09 17:54 - 2014-05-09 17:54 - 02347384 _____ (ESET) C:\Users\Julie\Downloads\esetsmartinstaller_csy(5).exe
2014-04-25 15:55 - 2014-04-25 15:55 - 00000000 ____D () C:\Users\Julie\Desktop\113julča
2014-04-24 14:10 - 2014-04-23 12:19 - 00043520 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2014-04-12 19:25 - 2014-04-12 19:25 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online
==================== One Month Modified Files and Folders =======
2014-05-12 09:44 - 2014-05-12 09:43 - 00012009 _____ () C:\Users\Julie\Desktop\FRST.txt
2014-05-12 09:44 - 2014-04-11 20:28 - 01248779 _____ () C:\Windows\WindowsUpdate.log
2014-05-12 09:43 - 2014-05-12 09:42 - 00000000 ____D () C:\FRST
2014-05-12 09:40 - 2014-05-12 09:42 - 00112640 _____ (forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
2014-05-12 09:39 - 2014-05-12 09:41 - 02066944 _____ (Farbar) C:\Users\Julie\Desktop\FRST64.exe
2014-05-12 09:37 - 2014-01-22 09:43 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Skype
2014-05-12 09:37 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-05-12 01:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-05-12 00:34 - 2013-12-18 23:57 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2508871071-1620209755-3458330456-1001
2014-05-11 23:21 - 2013-12-19 02:15 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-11 23:20 - 2014-05-11 22:43 - 00008519 _____ () C:\zoek-results.log
2014-05-11 23:20 - 2013-12-18 23:53 - 00000000 __RDO () C:\Users\Julie\SkyDrive
2014-05-11 23:19 - 2014-05-11 10:42 - 00002946 _____ () C:\Windows\PFRO.log
2014-05-11 23:19 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-11 22:55 - 2014-05-11 22:42 - 00000000 ____D () C:\zoek_backup
2014-05-11 22:55 - 2013-12-18 23:49 - 00000000 ____D () C:\Users\Julie
2014-05-11 22:42 - 2014-05-11 22:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-11 22:42 - 2014-05-11 22:42 - 01285120 _____ () C:\Users\Julie\Desktop\zoek.exe
2014-05-11 18:42 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-11 16:53 - 2014-05-11 16:53 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-05-11 16:49 - 2014-05-11 16:48 - 00000000 ____D () C:\AdwCleaner
2014-05-11 16:43 - 2014-05-11 16:47 - 01316991 _____ () C:\Users\Julie\Desktop\adwcleaner.exe
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\rsit
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\Program Files\trend micro
2014-05-11 15:03 - 2014-05-11 14:52 - 00000000 ____D () C:\Users\Julie\Desktop\RK_Quarantine
2014-05-11 14:59 - 2014-05-11 14:59 - 39935131 _____ (Hi-Rez Studios) C:\Users\Julie\Downloads\InstallHiRezGamesEnglish(1).exe
2014-05-11 14:52 - 2014-05-11 14:52 - 03972608 _____ () C:\Users\Julie\Downloads\RogueKiller(4).exe
2014-05-11 11:21 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Windows\Options
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-05-11 11:18 - 2013-12-19 00:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-11 10:50 - 2014-02-23 10:42 - 00000000 ____D () C:\Users\Julie\Desktop\Původní data aplikace Firefox
2014-05-11 10:40 - 2013-09-30 06:20 - 01745984 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-11 10:40 - 2013-09-30 05:57 - 00739924 _____ () C:\Windows\system32\perfh005.dat
2014-05-11 10:40 - 2013-09-30 05:57 - 00151610 _____ () C:\Windows\system32\perfc005.dat
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setupact.log
2014-05-10 21:42 - 2014-05-10 21:42 - 00001988 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-05-10 21:42 - 2013-12-19 02:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-05-10 21:42 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-10 21:41 - 2014-05-10 21:41 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-10 21:41 - 2014-05-10 21:41 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-10 21:41 - 2013-12-19 02:15 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-10 19:40 - 2014-01-23 22:22 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\.minecraft
2014-05-09 17:54 - 2014-05-09 17:54 - 02347384 _____ (ESET) C:\Users\Julie\Downloads\esetsmartinstaller_csy(5).exe
2014-04-25 15:55 - 2014-04-25 15:55 - 00000000 ____D () C:\Users\Julie\Desktop\113julča
2014-04-23 12:19 - 2014-04-24 14:10 - 00043520 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2014-04-23 02:24 - 2013-12-30 01:37 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-23 02:24 - 2013-12-30 01:37 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-12 19:25 - 2014-04-12 19:25 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online
2014-04-12 19:25 - 2014-03-17 19:14 - 00000000 ____D () C:\Program Files (x86)\Drakensang Online
2014-04-12 19:25 - 2014-03-08 15:15 - 00001984 _____ () C:\Users\Julie\Desktop\Drakensang Online.lnk
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
AlternateDataStreams: C:\Users\Julie\SkyDrive:ms-properties
==================== Security Center ==================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Julie\Desktop" je 55 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================
Ran by Julie (administrator) on JULINKA on 12-05-2014 09:43:58
Running from C:\Users\Julie\Desktop
Platform: Windows 8.1 Pro (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version: http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(GreenVantage LLC) D:\CPUgenie\CPUgenie.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20461_x64__8wekyb3d8bbwe\livecomm.exe
(Ghisler Software GmbH) D:\totalcmd\TOTALCMD.EXE
(forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3873704 2014-05-10] (AVAST Software)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKU\S-1-5-21-2508871071-1620209755-3458330456-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20924064 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-2508871071-1620209755-3458330456-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = seznam.cz
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = seznam.cz
SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = http://www.google.com/search?q={searchTerms}
SearchScopes: HKCU - {126AD505-4E16-4497-944B-5BA1EAE183D1} URL = http://encyklopedie.seznam.cz/search?q= ... arch_16194
SearchScopes: HKCU - {1758B189-998A-4CB5-9B40-A501776390FD} URL = http://search.seznam.cz/?q={searchTerms ... arch_16194
SearchScopes: HKCU - {5D2B6519-32E6-4C5E-953C-290AD0F48C4F} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
SearchScopes: HKCU - {5D8C45BD-1AB9-4939-9BB9-2ED68696E312} URL = http://www.zbozi.cz/?q={searchTerms}&r= ... arch_16194
SearchScopes: HKCU - {5FB9F448-6B35-4D35-88B1-83B65CB9ACD1} URL = http://www.novinky.cz/hledej?w={searchT ... arch_16194
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?q={searchT ... {startPage}
SearchScopes: HKCU - {D6DB4887-D03C-4DF9-B630-E240050E9767} URL = http://tv.seznam.cz/hledej?w={searchTer ... arch_16194
SearchScopes: HKCU - {E4F8CB08-A423-4110-B799-28B3CE57F032} URL = http://www.mapy.cz/?query={searchTerms} ... arch_16194
SearchScopes: HKCU - {EE815BFD-7521-4D40-907B-4F2D0D824E17} URL = http://www.firmy.cz/?q={searchTerms}&so ... arch_16194
SearchScopes: HKCU - {F71DDAB7-472A-4B1C-A545-96F12CFEE8FE} URL = http://slovnik.seznam.cz/?q={searchTerm ... arch_16194
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Julie\AppData\Roaming\Mozilla\Firefox\Profiles\j8kzt4ak.default-1399798244496
FF NewTab: hxxp://www.google.com/
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.com
FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Julie\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\heureka-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\mapy-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\seznam-cz.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\slunecnice-cz.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-12-19]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-10] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109048 2014-05-10] (AVAST Software)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 AmdTools64; C:\Windows\System32\drivers\AmdTools64.sys [47160 2008-04-28] (AMD, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-10] ()
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28184 2014-05-10] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-10] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [447888 2014-05-10] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-10] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-10] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-10] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-10] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-10] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-10] ()
S3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3888640 2014-02-14] (Qualcomm Atheros Communications, Inc.)
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
R3 CPUgenieDriver; D:\CPUgenie\NBFreezer.sys [14960 2010-05-11] (GreenVantage LLC)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [43520 2014-04-23] (Elex do Brasil Participações Ltda)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924512 2013-08-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
S3 winbondcir; C:\Windows\system32\DRIVERS\winbondcir.sys [46592 2007-03-28] (Winbond Electronics Corporation)
S1 iSafeKrnlKit; \??\C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-12 09:43 - 2014-05-12 09:44 - 00012009 _____ () C:\Users\Julie\Desktop\FRST.txt
2014-05-12 09:42 - 2014-05-12 09:43 - 00000000 ____D () C:\FRST
2014-05-12 09:42 - 2014-05-12 09:40 - 00112640 _____ (forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
2014-05-12 09:41 - 2014-05-12 09:39 - 02066944 _____ (Farbar) C:\Users\Julie\Desktop\FRST64.exe
2014-05-11 22:57 - 2014-05-11 22:42 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-11 22:43 - 2014-05-11 23:20 - 00008519 _____ () C:\zoek-results.log
2014-05-11 22:42 - 2014-05-11 22:55 - 00000000 ____D () C:\zoek_backup
2014-05-11 22:42 - 2014-05-11 22:42 - 01285120 _____ () C:\Users\Julie\Desktop\zoek.exe
2014-05-11 16:53 - 2014-05-11 16:53 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-11 16:48 - 2014-05-11 16:49 - 00000000 ____D () C:\AdwCleaner
2014-05-11 16:47 - 2014-05-11 16:43 - 01316991 _____ () C:\Users\Julie\Desktop\adwcleaner.exe
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\rsit
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\Program Files\trend micro
2014-05-11 14:59 - 2014-05-11 14:59 - 39935131 _____ (Hi-Rez Studios) C:\Users\Julie\Downloads\InstallHiRezGamesEnglish(1).exe
2014-05-11 14:52 - 2014-05-11 15:03 - 00000000 ____D () C:\Users\Julie\Desktop\RK_Quarantine
2014-05-11 14:52 - 2014-05-11 14:52 - 03972608 _____ () C:\Users\Julie\Downloads\RogueKiller(4).exe
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Windows\Options
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-05-11 11:18 - 2014-02-14 03:35 - 03888640 _____ (Qualcomm Atheros Communications, Inc.) C:\Windows\system32\Drivers\athwbx.sys
2014-05-11 10:42 - 2014-05-11 23:19 - 00002946 _____ () C:\Windows\PFRO.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setupact.log
2014-05-10 21:42 - 2014-05-10 21:42 - 00001988 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-05-10 21:41 - 2014-05-10 21:41 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-10 21:41 - 2014-05-10 21:41 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-05-09 17:54 - 2014-05-09 17:54 - 02347384 _____ (ESET) C:\Users\Julie\Downloads\esetsmartinstaller_csy(5).exe
2014-04-25 15:55 - 2014-04-25 15:55 - 00000000 ____D () C:\Users\Julie\Desktop\113julča
2014-04-24 14:10 - 2014-04-23 12:19 - 00043520 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2014-04-12 19:25 - 2014-04-12 19:25 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online
==================== One Month Modified Files and Folders =======
2014-05-12 09:44 - 2014-05-12 09:43 - 00012009 _____ () C:\Users\Julie\Desktop\FRST.txt
2014-05-12 09:44 - 2014-04-11 20:28 - 01248779 _____ () C:\Windows\WindowsUpdate.log
2014-05-12 09:43 - 2014-05-12 09:42 - 00000000 ____D () C:\FRST
2014-05-12 09:40 - 2014-05-12 09:42 - 00112640 _____ (forum.viry.cz) C:\Users\Julie\Desktop\FRSTLauncher.exe
2014-05-12 09:39 - 2014-05-12 09:41 - 02066944 _____ (Farbar) C:\Users\Julie\Desktop\FRST64.exe
2014-05-12 09:37 - 2014-01-22 09:43 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Skype
2014-05-12 09:37 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-05-12 01:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-05-12 00:34 - 2013-12-18 23:57 - 00003600 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2508871071-1620209755-3458330456-1001
2014-05-11 23:21 - 2013-12-19 02:15 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-05-11 23:20 - 2014-05-11 22:43 - 00008519 _____ () C:\zoek-results.log
2014-05-11 23:20 - 2013-12-18 23:53 - 00000000 __RDO () C:\Users\Julie\SkyDrive
2014-05-11 23:19 - 2014-05-11 10:42 - 00002946 _____ () C:\Windows\PFRO.log
2014-05-11 23:19 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-11 22:55 - 2014-05-11 22:42 - 00000000 ____D () C:\zoek_backup
2014-05-11 22:55 - 2013-12-18 23:49 - 00000000 ____D () C:\Users\Julie
2014-05-11 22:42 - 2014-05-11 22:57 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-05-11 22:42 - 2014-05-11 22:42 - 01285120 _____ () C:\Users\Julie\Desktop\zoek.exe
2014-05-11 18:42 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-11 16:53 - 2014-05-11 16:53 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-11 16:53 - 2014-05-11 16:53 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-05-11 16:49 - 2014-05-11 16:48 - 00000000 ____D () C:\AdwCleaner
2014-05-11 16:43 - 2014-05-11 16:47 - 01316991 _____ () C:\Users\Julie\Desktop\adwcleaner.exe
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\rsit
2014-05-11 16:17 - 2014-05-11 16:17 - 00000000 ____D () C:\Program Files\trend micro
2014-05-11 15:03 - 2014-05-11 14:52 - 00000000 ____D () C:\Users\Julie\Desktop\RK_Quarantine
2014-05-11 14:59 - 2014-05-11 14:59 - 39935131 _____ (Hi-Rez Studios) C:\Users\Julie\Downloads\InstallHiRezGamesEnglish(1).exe
2014-05-11 14:52 - 2014-05-11 14:52 - 03972608 _____ () C:\Users\Julie\Downloads\RogueKiller(4).exe
2014-05-11 11:21 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Windows\Options
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2014-05-11 11:18 - 2014-05-11 11:18 - 00000000 ____D () C:\Program Files (x86)\Atheros
2014-05-11 11:18 - 2013-12-19 00:06 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-11 10:50 - 2014-02-23 10:42 - 00000000 ____D () C:\Users\Julie\Desktop\Původní data aplikace Firefox
2014-05-11 10:40 - 2013-09-30 06:20 - 01745984 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-11 10:40 - 2013-09-30 05:57 - 00739924 _____ () C:\Windows\system32\perfh005.dat
2014-05-11 10:40 - 2013-09-30 05:57 - 00151610 _____ () C:\Windows\system32\perfc005.dat
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setuperr.log
2014-05-11 02:18 - 2014-05-11 02:18 - 00000000 _____ () C:\Windows\setupact.log
2014-05-10 21:42 - 2014-05-10 21:42 - 00001988 _____ () C:\Users\Public\Desktop\avast! Internet Security.lnk
2014-05-10 21:42 - 2013-12-19 02:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-05-10 21:42 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-10 21:41 - 2014-05-10 21:41 - 00447888 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-05-10 21:41 - 2014-05-10 21:41 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-05-10 21:41 - 2014-05-10 21:41 - 00028184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-05-10 21:41 - 2013-12-19 02:15 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-05-10 21:41 - 2013-12-19 02:15 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-05-10 19:40 - 2014-01-23 22:22 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\.minecraft
2014-05-09 17:54 - 2014-05-09 17:54 - 02347384 _____ (ESET) C:\Users\Julie\Downloads\esetsmartinstaller_csy(5).exe
2014-04-25 15:55 - 2014-04-25 15:55 - 00000000 ____D () C:\Users\Julie\Desktop\113julča
2014-04-23 12:19 - 2014-04-24 14:10 - 00043520 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeKrnlBoot.sys
2014-04-23 02:24 - 2013-12-30 01:37 - 00693240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-23 02:24 - 2013-12-30 01:37 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-12 19:25 - 2014-04-12 19:25 - 00000000 ____D () C:\Users\Julie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Drakensang Online
2014-04-12 19:25 - 2014-03-17 19:14 - 00000000 ____D () C:\Program Files (x86)\Drakensang Online
2014-04-12 19:25 - 2014-03-08 15:15 - 00001984 _____ () C:\Users\Julie\Desktop\Drakensang Online.lnk
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===
==================== Drive and Memory info ===================
==================== MBR and Partition Table ==================
==================== Scheduled Tasks (whitelisted) ==================
==================== Alternate Data Streams (whitelisted) ==================
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
AlternateDataStreams: C:\Users\Julie\SkyDrive:ms-properties
==================== Security Center ==================
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Disabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)
***** Velikost "Plochy" *****
Velikost slozky "C:\Users\Julie\Desktop" je 55 MB.
***** Startup Programs *****
***** Firewall rules *****
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
***** System Restore *****
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"Generalize_DisableSR"=dword:00000000
==================== End Of Log ==============================