Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-01-2015 02
Ran by admin (administrator) on ADMIN-TOSH on 14-01-2015 11:19:11
Running from C:\Users\admin\Desktop
Loaded Profile: admin (Available profiles: admin)
Platform: Windows 7 Home Premium (X64) OS Language: Čeština (Česká republika)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Toshiba Europe GmbH) C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\Teco.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Facebook) C:\Users\admin\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
(TOSHIBA CORPORATION.) C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
(TOSHIBA CORPORATION) C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(Společnost TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] => C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050000 2009-10-15] (Toshiba Europe GmbH)
HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [595816 2009-11-30] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [34648 2009-12-01] (TOSHIBA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8306208 2009-10-21] (Realtek Semiconductor)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [505696 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] => C:\Program Files\TOSHIBA\TBS\HSON.exe [52600 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] => C:\Program Files\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [910136 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1870120 2009-10-15] (Synaptics Incorporated)
HKLM\...\Run: [SmartFaceVWatcher] => C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1482592 2009-09-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [707416 2009-11-10] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] => C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [134032 2009-08-25] (Toshiba Europe GmbH)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [2903688 2010-07-02] (ESET)
HKLM\...\Run: [TNOD UP] => "C:\Program Files (x86)\TNod User & Password Finder\TNODUP.exe" /i
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [Kufaaf] => "C:\Users\admin\AppData\Roaming\Kubuadm\gefopo.exe"
HKLM\...\Run: [Kihaxyletuitwi] => "C:\Users\admin\AppData\Roaming\Momawei\enqugu.exe"
HKLM\...\Run: [Yhesemgy] => "C:\Users\admin\AppData\Roaming\Ixyqqa\mupuq.exe"
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-09-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SVPWUTIL] => C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe [352256 2009-08-12] (TOSHIBA)
HKLM-x32\...\Run: [HWSetup] => C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [423936 2009-06-02] (TOSHIBA Electronics, Inc.)
HKLM-x32\...\Run: [KeNotify] => C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TWebCamera] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840 2009-11-21] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\ESET <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files\ESET <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Trend Micro <====== ATTENTION
HKLM Group Policy restriction on software: C:\Documents and Settings\All Users\Application Data\McAfee <====== ATTENTION
HKLM Group Policy restriction on software: C:\Program Files (x86)\Trend Micro <====== ATTENTION
Winlogon\Notify\cmjahae-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\cmjahae.dll ()
Winlogon\Notify\cnjahae-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\cnjahae.dll ()
Winlogon\Notify\laominx-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\laominx.dll ()
Winlogon\Notify\laymegx-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\laymegx.dll ()
Winlogon\Notify\megxlay-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\megxlay.dll ()
Winlogon\Notify\xmeglay-x32: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\xmeglay.dll ()
HKU\S-1-5-18\...\Run: [TOSHIBA Online Product Information] => C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe [6203296 2009-08-12] (TOSHIBA)
HKU\S-1-5-18\...\Run: [JuseZvucu] => regsvr32.exe "C:\ProgramData\JuseZvucu\BaqoFcus.xqd"
HKU\S-1-5-18\...\Run: [laominx] => rundll32 "C:\Windows\system32\config\systemprofile\AppData\Local\laominx.dll",laominx <===== ATTENTION
HKU\S-1-5-18\...\Run: [laymegx] => rundll32 "C:\Windows\system32\config\systemprofile\AppData\Local\laymegx.dll",laymegx <===== ATTENTION
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
ShortcutTarget: Facebook Messenger.lnk -> C:\Users\admin\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe (Facebook)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4276310980-1373315075-2881649484-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKU\S-1-5-21-4276310980-1373315075-2881649484-1000\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
URLSearchHook: HKLM-x32 - DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files (x86)\DVDVideoSoft\tbDVDV.dll No File
URLSearchHook: HKU\S-1-5-21-4276310980-1373315075-2881649484-1000 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4276310980-1373315075-2881649484-1000 -> {38C7CBF5-114D-4C64-80E4-EE7795D89208} URL =
http://rover.ebay.com/rover/1/710-71511 ... earchTerms}
SearchScopes: HKU\S-1-5-21-4276310980-1373315075-2881649484-1000 -> {95344AD6-CA51-45FD-B624-344AAA5E2895} URL =
http://www.amazon.co.uk/gp/search?ie=UT ... nkCode=ur2
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: STATISTICA Browser Helper -> {990A8747-93BF-4EF7-B72E-94A6884B98C2} -> C:\Program Files\StatSoft\STATISTICA 12\StaBHO.dll (StatSoft, Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealPlayer Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
BHO-x32: QipLI Class -> {6B5863A0-C43F-4C0A-982B-CC0E9125783F} -> C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\qstatsrv.dll (TODO: <Company name>)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: STATISTICA Browser Helper -> {990A8747-93BF-4EF7-B72E-94A6884B98C2} -> C:\Program Files\StatSoft\STATISTICA 12\Support\StaBHO.dll (StatSoft, Inc.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: SmileysWeLoveToolbar -> {E4EF8A64-0A30-48F5-B3FE-5FDA978DA775} -> C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll No File
BHO-x32: DVDVideoSoft Toolbar -> {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} -> C:\Program Files (x86)\DVDVideoSoft\tbDVDV.dll No File
Toolbar: HKLM-x32 - DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:\Program Files (x86)\DVDVideoSoft\tbDVDV.dll No File
Toolbar: HKLM-x32 - SmileysWeLove - {CF0F43AB-9C23-4D7B-8040-201B82844854} - C:\Program Files (x86)\Smileys We Love Toolbar for IE\adxloader.dll No File
DPF: HKLM-x32 {C345E174-3E87-4F41-A01C-B066A90A49B4}
http://trial.trymicrosoftoffice.com/tri ... /wrc32.ocx
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\Windows\SysWOW64\btxppanel.dll (Broadcom Corporation.)
Tcpip\..\Interfaces\{21D58735-AE15-4842-9829-CBBD2157E4C6}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{4A58A413-B75C-4A66-9274-C26982A7D85A}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{62B8830F-0C16-460D-9FBF-AC757AC06575}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9xepabbp.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=12.0.1.609 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprjplug;version=12.0.1.609 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprphtml5videoshim;version=12.0.1.609 -> C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpjplug;version=12.0.1.609 -> C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-4276310980-1373315075-2881649484-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-4276310980-1373315075-2881649484-1000: facebook.com/fbDesktopPlugin -> C:\Users\admin\AppData\Local\Facebook\Messenger\2.1.4814.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF Extension: Skype extension for Firefox - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2014-12-09]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF Extension: RealPlayer Browser Record Plugin - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010-12-05]
FF HKLM-x32\...\Thunderbird\Extensions: [
eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010-09-27]
FF HKU\S-1-5-21-4276310980-1373315075-2881649484-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://search.babylon.com/?affID=112465&tt=3012_2&babsrc=HP_ss&mntrId=0881377f00000000000070f1a1466265
CHR StartupUrls: Default -> "hxxp://search.chatzum.com"
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.140.8) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeploytk.dll (Sun Microsystems, Inc.)
CHR Plugin: (Java(TM) Platform SE 6 U14) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Microsoft® Windows Media Player Firefox Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll (Microsoft Corporation)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll (RealNetworks, Inc.)
CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll (RealNetworks, Inc.)
CHR Plugin: (AVG SiteSafety plugin) - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.0.2\\npsitesafety.dll No File
CHR Plugin: (DivX Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Live® Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\admin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-15]
CHR Extension: (Vyhledávání Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-15]
CHR Extension: (RealPlayer HTML5Video Downloader Extension) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk [2011-02-14]
CHR Extension: (Peněženka Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-15]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Chrome\Ext\rphtml5video.crx [2010-12-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 EhttpSrv; C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe [42360 2010-07-02] (ESET)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [810144 2010-07-02] (ESET)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S3 ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
R2 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [116104 2009-10-15] (Toshiba Europe GmbH)
S2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]
S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 ALG; C:\Windows\System32\alg.exe [79360 2009-07-14] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S2 BTSERIAL; C:\Windows\SysWOW64\drivers\btserial.sys [23271 2004-11-29] (Broadcom Corporation.) [File not signed]
S2 BTSLBCSP; C:\Windows\SysWOW64\drivers\btslbcsp.sys [222876 2004-11-29] (Broadcom Corporation.) [File not signed]
R2 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [166984 2010-06-24] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [139704 2010-04-28] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [169592 2010-04-28] (ESET)
R3 Epfwndis; C:\Windows\System32\DRIVERS\Epfwndis.sys [33608 2010-04-28] (ESET)
R2 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [50600 2010-04-28] (ESET)
U5 Netlogon; C:\Windows\system32\lsass.exe [31232 2011-11-17] (Microsoft Corporation)
U5 ProtectedStorage; C:\Windows\system32\lsass.exe [31232 2011-11-17] (Microsoft Corporation)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-11-09] () [File not signed]
S1 StarOpen; C:\Windows\SysWow64\Drivers\StarOpen.sys [5632 2006-07-24] () [File not signed]
U3 ahrortp9; C:\Windows\System32\Drivers\ahrortp9.sys [0 ] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-14 11:19 - 2015-01-14 11:19 - 00026677 _____ () C:\Users\admin\Desktop\FRST.txt
2015-01-14 11:18 - 2015-01-14 11:19 - 00000000 ____D () C:\FRST
2015-01-14 11:18 - 2015-01-14 11:17 - 02124288 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2015-01-14 10:19 - 2015-01-14 10:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-14 10:18 - 2015-01-14 11:04 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-01-14 10:18 - 2015-01-14 11:01 - 00000000 ____D () C:\Users\admin\Desktop\mbar
2015-01-14 10:18 - 2015-01-14 10:18 - 00135384 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-14 10:18 - 2015-01-14 10:18 - 00096472 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-01-14 10:17 - 2015-01-14 10:16 - 16448208 _____ (Malwarebytes Corp.) C:\Users\admin\Desktop\mbar-1.08.2.1001.exe
2015-01-13 23:56 - 2015-01-13 23:56 - 00019557 _____ () C:\ComboFix.txt
2015-01-13 23:47 - 2015-01-13 23:49 - 00000000 ____D () C:\ProgramData\JuseZvucu
2015-01-13 23:41 - 2015-01-13 23:41 - 00001204 _____ () C:\CF-Submit.htm
2015-01-13 22:55 - 2015-01-14 11:07 - 00016236 _____ () C:\Windows\WindowsUpdate.log
2015-01-13 22:41 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-01-13 22:41 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-01-13 22:41 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-01-13 22:41 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-01-13 22:41 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-01-13 22:41 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-01-13 22:41 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-01-13 22:41 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-01-13 22:16 - 2015-01-14 00:02 - 00000000 ____D () C:\Qoobox
2015-01-13 22:16 - 2015-01-13 23:47 - 00000000 ____D () C:\Windows\erdnt
2015-01-13 22:16 - 2015-01-13 22:14 - 05609736 ____R (Swearware) C:\Users\admin\Desktop\ComboFix.exe
2015-01-13 21:34 - 2015-01-13 21:34 - 03148854 _____ () C:\Users\admin\Documents\Decrypt All Files mmjujvj.bmp
2015-01-13 21:34 - 2015-01-13 21:34 - 00001266 _____ () C:\Users\admin\Documents\Decrypt All Files mmjujvj.txt
2015-01-13 20:57 - 2015-01-13 20:57 - 00003264 _____ () C:\Users\admin\Desktop\AdwCleaner[S0].TXT.mmjujvj
2015-01-13 20:57 - 2015-01-13 20:20 - 00018480 _____ () C:\Users\admin\Desktop\Logfile of random.DOCX.mmjujvj
2015-01-13 20:57 - 2015-01-13 20:18 - 00009072 _____ () C:\Users\admin\Desktop\RSIT.TXT.mmjujvj
2015-01-13 20:53 - 2015-01-14 11:03 - 00002942 _____ () C:\Windows\PFRO.log
2015-01-13 20:43 - 2015-01-13 20:59 - 00000000 ____D () C:\AdwCleaner
2015-01-13 20:09 - 2015-01-13 21:29 - 00000000 ____D () C:\rsit
2015-01-13 20:09 - 2015-01-13 20:09 - 00000000 ____D () C:\Program Files (x86)\trend micro
2015-01-13 20:08 - 2015-01-13 19:54 - 01107968 _____ () C:\Users\admin\Desktop\RSIT.exe
2015-01-13 20:04 - 2015-01-14 11:03 - 00000336 _____ () C:\Windows\setupact.log
2015-01-13 20:04 - 2015-01-13 20:04 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-13 20:03 - 2015-01-09 21:16 - 02737120 _____ () C:\Users\admin\Desktop\DSCN1225.JPG.wdfljvj
2015-01-13 20:03 - 2015-01-07 22:15 - 02286576 _____ () C:\Users\admin\Downloads\ORGANICKÁ CHEMIE.DOCX.wdfljvj
2015-01-13 20:03 - 2015-01-07 22:14 - 01213136 _____ () C:\Users\admin\Downloads\Vypracovane_otazky organa.DOC.wdfljvj
2015-01-13 20:03 - 2015-01-07 14:45 - 01638528 _____ () C:\Users\admin\Downloads\3_Organick_slou_eniny_dus_ku_a_kysl_ku (1).PDF.wdfljvj
2015-01-13 20:03 - 2015-01-07 14:18 - 01638528 _____ () C:\Users\admin\Downloads\3_Organick_slou_eniny_dus_ku_a_kysl_ku.PDF.wdfljvj
2015-01-13 20:03 - 2015-01-07 14:10 - 02052240 _____ () C:\Users\admin\Downloads\Lipidy.PDF.wdfljvj
2015-01-13 20:03 - 2015-01-07 10:44 - 01357056 _____ () C:\Users\admin\Downloads\sacharidy-bez_animaci.PDF.wdfljvj
2015-01-13 20:03 - 2015-01-06 19:45 - 01945296 _____ () C:\Users\admin\Downloads\prilohy_26561.ZIP.wdfljvj
2015-01-13 20:03 - 2015-01-04 22:05 - 01175040 _____ () C:\Users\admin\Downloads\zaverecna_prace.PDF.wdfljvj
2015-01-13 20:03 - 2015-01-04 10:17 - 02316784 _____ () C:\Users\admin\Downloads\Okruhy_ot_zek_k_organick_sti_zkou_ky-1.DOCX.wdfljvj
2015-01-13 20:03 - 2015-01-04 09:42 - 01373088 _____ () C:\Users\admin\Downloads\2_Organick_chemie-2pred.PDF.wdfljvj
2015-01-13 20:03 - 2015-01-04 09:42 - 01302144 _____ () C:\Users\admin\Downloads\4_Karboxylov_fci_der (2).PDF.wdfljvj
2015-01-13 20:03 - 2015-01-04 09:41 - 01302144 _____ () C:\Users\admin\Downloads\4_Karboxylov_fci_der (1).PDF.wdfljvj
2015-01-13 20:03 - 2012-04-18 01:15 - 01559088 _____ () C:\Users\admin\Documents\UPRAVENO – kopie.PDF.wdfljvj
2015-01-13 20:03 - 2012-02-23 21:05 - 01636224 _____ () C:\Users\admin\Downloads\Nova slozka.ZIP.wdfljvj
2015-01-13 19:06 - 2015-01-13 19:06 - 00000000 ____D () C:\Users\admin\AppData\Local\RKB
2015-01-13 17:46 - 2015-01-13 21:34 - 01121537 _____ () C:\ProgramData\ihvhzvh.html
2015-01-13 17:43 - 2015-01-13 17:43 - 00002866 _____ () C:\Windows\System32\Tasks\pbklicg
2015-01-12 17:08 - 2015-01-12 17:08 - 00008562 _____ () C:\Users\HELP_DECRYPT.HTML
2015-01-12 17:08 - 2015-01-12 17:08 - 00008562 _____ () C:\Users\AppData\HELP_DECRYPT.HTML
2015-01-12 17:08 - 2015-01-12 17:08 - 00008562 _____ () C:\Users\admin\HELP_DECRYPT.HTML
2015-01-12 17:08 - 2015-01-12 17:08 - 00008562 _____ () C:\HELP_DECRYPT.HTML
2015-01-12 17:08 - 2015-01-12 17:08 - 00000280 _____ () C:\Users\HELP_DECRYPT.URL
2015-01-12 17:08 - 2015-01-12 17:08 - 00000280 _____ () C:\Users\AppData\HELP_DECRYPT.URL
2015-01-12 17:08 - 2015-01-12 17:08 - 00000280 _____ () C:\Users\admin\HELP_DECRYPT.URL
2015-01-12 17:08 - 2015-01-12 17:08 - 00000280 _____ () C:\HELP_DECRYPT.URL
2015-01-12 14:41 - 2015-01-12 14:41 - 00008562 _____ () C:\Users\admin\Downloads\HELP_DECRYPT.HTML
2015-01-12 14:41 - 2015-01-12 14:41 - 00000280 _____ () C:\Users\admin\Downloads\HELP_DECRYPT.URL
2015-01-12 14:40 - 2015-01-12 14:40 - 00008562 _____ () C:\Users\admin\Documents\HELP_DECRYPT.HTML
2015-01-12 14:40 - 2015-01-12 14:40 - 00000280 _____ () C:\Users\admin\Documents\HELP_DECRYPT.URL
2015-01-12 14:23 - 2015-01-12 17:08 - 00001376 _____ () C:\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 14:23 - 2015-01-12 13:52 - 00001376 _____ () C:\ProgramData\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 14:23 - 2010-12-02 13:41 - 00021168 _____ () C:\Program Files (x86)\EULA.CS.wdfljvj
2015-01-12 14:23 - 2010-03-11 12:35 - 00000416 ____H () C:\SWSTAMP.TXT.wdfljvj
2015-01-12 13:57 - 2015-01-12 13:57 - 00008562 _____ () C:\Users\admin\AppData\Roaming\HELP_DECRYPT.HTML
2015-01-12 13:57 - 2015-01-12 13:57 - 00008562 _____ () C:\Users\admin\AppData\HELP_DECRYPT.HTML
2015-01-12 13:57 - 2015-01-12 13:57 - 00000280 _____ () C:\Users\admin\AppData\Roaming\HELP_DECRYPT.URL
2015-01-12 13:57 - 2015-01-12 13:57 - 00000280 _____ () C:\Users\admin\AppData\HELP_DECRYPT.URL
2015-01-12 13:56 - 2015-01-12 13:56 - 00008562 _____ () C:\Users\admin\AppData\Local\HELP_DECRYPT.HTML
2015-01-12 13:56 - 2015-01-12 13:56 - 00000280 _____ () C:\Users\admin\AppData\Local\HELP_DECRYPT.URL
2015-01-12 13:52 - 2015-01-12 13:52 - 00008562 _____ () C:\ProgramData\HELP_DECRYPT.HTML
2015-01-12 13:52 - 2015-01-12 13:52 - 00000280 _____ () C:\ProgramData\HELP_DECRYPT.URL
2015-01-11 13:03 - 2015-01-11 13:03 - 00003814 _____ () C:\Windows\System32\Tasks\Security Center Update - 3425793768
2015-01-11 13:03 - 2014-02-24 01:04 - 00507576 ____N (Eraem Corniratu) C:\Windows\SysWOW64\ixykwuot.exe
2015-01-08 14:57 - 2015-01-08 14:57 - 00003808 _____ () C:\Windows\System32\Tasks\Security Center Update - 3998176165
2015-01-08 14:57 - 2014-01-19 11:43 - 00509100 ____N (Eraem Corniratu) C:\Windows\SysWOW64\weirkay.exe
2015-01-08 09:09 - 2015-01-08 09:09 - 00003818 _____ () C:\Windows\System32\Tasks\Security Center Update - 514026233
2015-01-08 09:09 - 2011-01-16 19:54 - 00508951 ____N (Eraem Corniratu) C:\Windows\SysWOW64\fautkotybi.exe
2015-01-07 14:44 - 2015-01-13 20:40 - 00000000 ____D () C:\Users\admin\Desktop\ORGANIKA
2015-01-07 08:56 - 2015-01-07 08:56 - 00003814 _____ () C:\Windows\System32\Tasks\Security Center Update - 607701921
2015-01-07 08:56 - 2014-07-31 09:59 - 00505504 ____N (Eraem Corniratu) C:\Windows\SysWOW64\xireab.exe
2015-01-07 08:53 - 2015-01-07 08:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-01-07 08:52 - 2015-01-07 08:52 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2015-01-07 08:52 - 2015-01-07 08:52 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2015-01-07 08:49 - 2015-01-07 08:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2015-01-06 19:46 - 2015-01-13 19:24 - 00000000 ____D () C:\Users\admin\Desktop\6.1
2015-01-06 08:55 - 2015-01-13 22:50 - 00000000 ____D () C:\42686079
2015-01-06 08:21 - 2015-01-06 08:21 - 00000000 ____D () C:\Windows\SysWOW64\ຐ֭ೀ֭sers
2015-01-05 18:36 - 2015-01-05 18:38 - 35432576 _____ () C:\Users\admin\Downloads\Koně-1.PPT.mmjujvj
2015-01-05 18:24 - 2015-01-13 21:10 - 00000000 ____D () C:\Users\admin\Desktop\hygiena
2015-01-04 15:17 - 2015-01-13 21:07 - 00000000 ____D () C:\Users\admin\Desktop\exo 6-11
2015-01-04 15:17 - 2015-01-13 20:51 - 00000000 ____D () C:\Users\admin\Desktop\exo1-5
2015-01-04 15:15 - 2015-01-04 15:16 - 20022832 _____ () C:\Users\admin\Downloads\prilohy_390.ZIP.mmjujvj
2015-01-03 21:26 - 2015-01-03 21:26 - 00001725 _____ () C:\Users\admin\Desktop\Computer.lnk
2014-12-30 17:07 - 2015-01-13 20:28 - 00000000 ____D () C:\Users\admin\Desktop\30122014
2014-12-30 16:41 - 2015-01-12 13:47 - 00000761 _____ () C:\Windows\system32\Drivers\etc\hosts.txt
2014-12-30 16:34 - 2014-12-30 16:35 - 53898616 _____ () C:\Users\admin\Downloads\Nepotvrzeno 2911.crdownload
2014-12-30 16:33 - 2014-12-30 16:35 - 936785696 _____ () C:\Users\admin\Desktop\Anorganická a organická chemie.ZIP.mmjujvj
2014-12-23 14:44 - 2014-12-23 14:44 - 00000000 ____D () C:\Users\admin\AppData\Roaming\CrystalIdea Software
2014-12-22 23:01 - 2014-12-22 23:01 - 00499712 ____N () C:\Windows\fjEeGHhRviMexXc.exe
2014-12-22 08:46 - 2014-12-22 08:46 - 00002121 _____ () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Menu.lnk
2014-12-19 19:00 - 2014-12-19 19:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-12-19 18:59 - 2014-12-19 19:01 - 00000000 ____D () C:\ProgramData\Oracle
2014-12-18 20:35 - 2014-12-18 20:35 - 00003808 _____ () C:\Windows\System32\Tasks\Security Center Update - 591574539
2014-12-16 20:12 - 2014-12-16 20:12 - 00000000 ____D () C:\found.000
2014-12-16 07:54 - 2015-01-03 22:47 - 00934704 _____ () C:\Users\admin\AppData\Local\f5e83w4ef.dat
2014-12-15 20:53 - 2014-12-15 20:53 - 00004651 _____ () C:\Users\admin\how_decrypt.html
2014-12-15 20:53 - 2014-12-15 20:53 - 00004651 _____ () C:\Users\admin\AppData\Local\how_decrypt.html
2014-12-15 20:49 - 2014-12-15 20:49 - 00003808 _____ () C:\Windows\System32\Tasks\Security Center Update - 3741571091
2014-12-15 19:53 - 2015-01-13 20:24 - 00000000 ____D () C:\Users\admin\Desktop\eko zk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-14 11:11 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-14 11:11 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-14 11:05 - 2010-09-27 14:37 - 00000952 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-14 11:04 - 2010-09-27 14:37 - 00000948 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-01-14 11:03 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-14 11:01 - 2010-09-27 16:41 - 00000000 ____D () C:\Program Files (x86)\TNod User & Password Finder
2015-01-14 10:16 - 2012-04-17 18:55 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4276310980-1373315075-2881649484-1000UA.job
2015-01-13 23:49 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-01-13 23:48 - 2009-07-14 03:34 - 77066240 _____ () C:\Windows\system32\config\software.bak
2015-01-13 23:48 - 2009-07-14 03:34 - 21495808 _____ () C:\Windows\system32\config\system.bak
2015-01-13 23:48 - 2009-07-14 03:34 - 03862528 _____ () C:\Windows\system32\config\default.bak
2015-01-13 23:48 - 2009-07-14 03:34 - 00061440 _____ () C:\Windows\system32\config\sam.bak
2015-01-13 23:48 - 2009-07-14 03:34 - 00028672 _____ () C:\Windows\system32\config\security.bak
2015-01-13 23:00 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-01-13 22:02 - 2012-04-17 18:55 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-4276310980-1373315075-2881649484-1000Core.job
2015-01-13 21:29 - 2011-09-19 20:06 - 00000000 ____D () C:\Users\admin\Desktop\ŠKOLA
2015-01-13 21:29 - 2011-02-02 18:08 - 00000000 ____D () C:\Users\admin\Desktop\ZDENDA
2015-01-13 21:15 - 2012-06-26 22:15 - 00000000 ____D () C:\Users\admin\Desktop\ostatní
2015-01-13 21:10 - 2010-09-30 10:26 - 00000000 ____D () C:\Users\admin\Documents\ČZU ABPS
2015-01-13 21:04 - 2013-07-17 21:05 - 00000000 ____D () C:\Users\admin\Desktop\promoce
2015-01-13 21:04 - 2013-05-31 12:30 - 00000000 ____D () C:\Users\admin\Desktop\nor
2015-01-13 20:57 - 2010-04-08 14:20 - 00000000 ____D () C:\ProgramData\ATI
2015-01-13 20:52 - 2013-05-23 16:34 - 00000000 ____D () C:\Users\admin\Desktop\best
2015-01-13 20:50 - 2010-10-31 19:49 - 00000000 ____D () C:\ProgramData\ICQ
2015-01-13 20:46 - 2012-08-31 07:57 - 00000000 ____D () C:\Users\admin\Desktop\N
2015-01-13 20:37 - 2013-07-23 21:44 - 00000000 ____D () C:\Users\admin\Desktop\mobil
2015-01-13 20:32 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-13 20:29 - 2014-08-17 19:23 - 00000000 ____D () C:\Users\admin\Desktop\Od Zdendy Django + války
2015-01-13 20:27 - 2013-12-02 21:30 - 00000000 ____D () C:\Users\admin\Desktop\podzim 2013
2015-01-13 20:22 - 2014-08-07 15:50 - 00000000 ____D () C:\Users\admin\Desktop\Zoo Dvůr Králové 7.8.2014
2015-01-13 20:00 - 2010-09-27 19:21 - 00000000 ____D () C:\Users\admin\AppData\Local\MediaMonkey
2015-01-13 19:59 - 2011-09-26 19:46 - 00000000 ____D () C:\Windows\Minidump
2015-01-13 19:37 - 2014-02-10 20:30 - 00000000 ____D () C:\Users\admin\Desktop\prilohy_17781
2015-01-13 19:32 - 2014-06-17 11:55 - 00000000 ____D () C:\Users\admin\Desktop\Matěj
2015-01-13 19:28 - 2014-09-10 09:47 - 00000000 ____D () C:\Users\admin\Desktop\Custer na FB
2015-01-13 19:28 - 2013-10-11 20:01 - 00000000 ____D () C:\Users\admin\Desktop\1. Mgr
2015-01-13 19:26 - 2014-08-25 08:22 - 00000000 ____D () C:\Users\admin\Desktop\CUSTER
2015-01-13 19:18 - 2014-11-10 17:33 - 00000000 ____D () C:\Users\admin\Desktop\DP
2015-01-13 19:18 - 2013-01-08 07:45 - 00000000 ____D () C:\Users\admin\AppData\Roaming\MyHeritage
2015-01-13 19:18 - 2012-07-14 20:18 - 00000000 ____D () C:\Users\admin\Documents\samsung
2015-01-13 19:18 - 2011-09-05 17:42 - 00000000 ____D () C:\Users\admin\Documents\Spartan
2015-01-13 19:18 - 2010-10-04 22:44 - 00000000 ____D () C:\Users\admin\AppData\Roaming\BitTorrent
2015-01-13 19:18 - 2010-09-27 17:03 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Mozilla
2015-01-13 19:17 - 2014-12-10 11:33 - 00000000 ____D () C:\Users\admin\Desktop\Anorganická a organická chemie
2015-01-13 19:17 - 2012-09-01 08:07 - 00000000 ____D () C:\Users\admin\AppData\Roaming\eu.myphotobook.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
2015-01-13 19:17 - 2012-05-03 21:28 - 00000000 ____D () C:\Users\admin\Desktop\hry
2015-01-13 19:17 - 2011-02-23 12:53 - 00000000 ____D () C:\Users\admin\Downloads\Zoo Tycoon 2
2015-01-13 19:17 - 2011-01-09 14:22 - 00000000 ____D () C:\Users\admin\Documents\DVDVideoSoft
2015-01-13 19:17 - 2010-12-26 23:41 - 00000000 ____D () C:\Users\admin\Documents\EA Games
2015-01-13 19:17 - 2010-12-05 16:19 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Real
2015-01-13 19:17 - 2010-11-07 11:59 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Samsung
2015-01-13 19:17 - 2010-10-04 20:52 - 00000000 ____D () C:\Users\admin\AppData\Roaming\YoudaGames
2015-01-13 19:17 - 2010-09-27 23:13 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Adobe
2015-01-13 19:17 - 2010-09-27 19:39 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Skype
2015-01-13 19:17 - 2010-09-04 17:30 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Toshiba
2015-01-13 19:17 - 2010-09-04 12:38 - 00000000 ____D () C:\Users\admin
2015-01-13 19:15 - 2013-09-16 18:54 - 00000000 ____D () C:\Users\admin\AppData\Local\Pokki
2015-01-13 19:15 - 2010-09-27 17:03 - 00000000 ____D () C:\Users\admin\AppData\Local\Mozilla
2015-01-13 19:13 - 2012-04-17 18:54 - 00000000 ____D () C:\Users\admin\AppData\Local\Facebook
2015-01-13 19:13 - 2010-09-27 13:56 - 00000000 ____D () C:\Users\admin\AppData\Local\Microsoft Games
2015-01-13 19:13 - 2010-09-27 13:28 - 00000000 ____D () C:\Users\admin\AppData\Local\Google
2015-01-13 19:12 - 2013-11-25 18:38 - 00000000 ____D () C:\PC TRANSLATOR DEMO
2015-01-13 19:12 - 2010-03-11 12:18 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office Suite Activation Assistant
2015-01-13 19:11 - 2010-03-11 12:04 - 00000000 ____D () C:\Program Files (x86)\eBay
2015-01-13 17:46 - 2010-03-11 12:15 - 00000000 ____D () C:\Works
2015-01-13 17:45 - 2012-12-26 21:28 - 00000000 ____D () C:\ProgramData\MyHeritage
2015-01-13 17:45 - 2010-10-11 22:20 - 00000000 ____D () C:\ProgramData\DivX
2015-01-13 17:45 - 2010-10-11 15:33 - 00000000 ____D () C:\Program Files (x86)\Miranda IM
2015-01-13 17:45 - 2010-09-27 19:39 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-13 17:45 - 2010-09-27 19:39 - 00000000 ____D () C:\ProgramData\Skype
2015-01-13 17:45 - 2010-09-27 19:21 - 00000000 ____D () C:\Program Files (x86)\MediaMonkey
2015-01-13 17:45 - 2010-09-27 14:41 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-13 17:45 - 2010-04-08 14:36 - 00000000 ____D () C:\ProgramData\TOSHIBA
2015-01-13 17:45 - 2010-04-08 14:19 - 00000000 ____D () C:\Program Files (x86)\ATI Technologies
2015-01-13 17:45 - 2010-03-11 12:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Works
2015-01-13 17:45 - 2010-03-11 12:10 - 00000000 ____D () C:\ProgramData\SiteAdvisor
2015-01-13 17:45 - 2010-03-11 11:11 - 00000000 ____D () C:\Toshiba
2015-01-13 17:44 - 2010-03-11 12:06 - 00000000 ____D () C:\Program Files (x86)\Toshiba TEMPRO
2015-01-12 17:08 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 17:08 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\AppData\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 17:08 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 14:41 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\Downloads\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 14:40 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\Documents\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 14:10 - 2009-07-14 06:08 - 00032598 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-01-12 13:57 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\AppData\Roaming\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 13:57 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\AppData\HELP_DECRYPT.TXT.wdfljvj
2015-01-12 13:56 - 2012-03-08 08:12 - 00001376 _____ () C:\Users\admin\AppData\Local\HELP_DECRYPT.TXT.wdfljvj
2015-01-09 22:26 - 2012-03-08 08:12 - 00409568 _____ () C:\Users\admin\Downloads\aminy01.DOC.wdfljvj
2015-01-09 18:41 - 2012-03-08 08:12 - 00116320 _____ () C:\Users\admin\Desktop\10614273_10203281861630849_3064998190579993020_n.JPG.wdfljvj
2015-01-08 20:01 - 2012-03-08 08:12 - 00653856 _____ () C:\Users\admin\Downloads\objednavka_vysetreni_vzorku.DOC.wdfljvj
2015-01-08 20:00 - 2012-03-08 08:12 - 00078192 _____ () C:\Users\admin\Downloads\olv_vzor_1_vzorky (1).DOC.wdfljvj
2015-01-08 19:55 - 2012-03-08 08:12 - 00078192 _____ () C:\Users\admin\Downloads\olv_vzor_1_vzorky.DOC.wdfljvj
2015-01-07 22:13 - 2012-03-08 08:12 - 00957280 _____ () C:\Users\admin\Downloads\org. zprac. okruhy.DOCX.wdfljvj
2015-01-07 14:44 - 2012-03-08 08:12 - 00199776 _____ () C:\Users\admin\Downloads\4_Tetrasubstituovan_deriv_ty_methanu.PDF.wdfljvj
2015-01-07 14:30 - 2012-03-08 08:12 - 00068976 _____ () C:\Users\admin\Downloads\otazkynazkousku(czuborec.cz-81c6d).DOC.wdfljvj
2015-01-07 14:28 - 2012-03-08 08:12 - 00070512 _____ () C:\Users\admin\Downloads\chemietahak(czuborec.cz-91ppd).DOC.wdfljvj
2015-01-07 14:25 - 2012-03-08 08:12 - 00037568 _____ () C:\Users\admin\Downloads\karboxylovekyseliny--(czuborec.cz-a65y7).doc.ZIP.wdfljvj
2015-01-07 14:24 - 2012-03-08 08:12 - 00494592 _____ () C:\Users\admin\Downloads\bilkoviny(czuborec.cz-a3196).DOC.wdfljvj
2015-01-07 14:23 - 2012-03-08 08:12 - 00067952 _____ () C:\Users\admin\Downloads\vzorovy_test(czuborec.cz-j5frs).DOC.wdfljvj
2015-01-07 14:23 - 2012-03-08 08:12 - 00064880 _____ () C:\Users\admin\Downloads\organika-test(czuborec.cz-u74ld).DOC.wdfljvj
2015-01-07 14:21 - 2012-03-08 08:12 - 00136000 _____ () C:\Users\admin\Downloads\zkouska_chemie_vypracovane(czuborec.cz-sxl2i).doc.ZIP.wdfljvj
2015-01-07 09:53 - 2012-03-08 08:12 - 00769776 _____ () C:\Users\admin\Downloads\1_Organick_chemie-1 (3).PDF.wdfljvj
2015-01-07 09:52 - 2012-03-08 08:12 - 00025440 _____ () C:\Users\admin\Downloads\k_organice_.DOC.wdfljvj
2015-01-07 09:51 - 2012-03-08 08:12 - 00028000 _____ () C:\Users\admin\Downloads\Okruhy_ot_zek_k_organick_sti_zkou_ky (2).DOC.wdfljvj
2015-01-07 09:50 - 2012-03-08 08:12 - 00011136 _____ () C:\Users\admin\Downloads\AF 2015.XLSX.wdfljvj
2015-01-06 18:57 - 2010-12-05 16:20 - 00003344 _____ () C:\Windows\System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-4276310980-1373315075-2881649484-1000
2015-01-06 18:57 - 2010-12-05 16:20 - 00003210 _____ () C:\Windows\System32\Tasks\RealUpgradeLogonTaskS-1-5-21-4276310980-1373315075-2881649484-1000
2015-01-06 08:21 - 2012-07-20 20:58 - 00011743 _____ () C:\Windows\SysWOW64\debug.log
2015-01-04 21:06 - 2012-03-08 08:12 - 00028000 _____ () C:\Users\admin\Downloads\Okruhy_ot_zek_k_organick_sti_zkou_ky (1).DOC.wdfljvj
2015-01-04 15:20 - 2014-12-09 20:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-04 15:20 - 2013-06-05 09:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-04 15:20 - 2012-09-24 10:56 - 00000000 ____D () C:\Program Files (x86)\Photo Story 3 for Windows
2015-01-04 15:20 - 2012-09-21 11:18 - 00000000 ____D () C:\Program Files (x86)\Nero
2015-01-04 15:20 - 2011-09-05 14:05 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2015-01-04 15:20 - 2011-02-23 13:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2015-01-04 15:20 - 2011-01-31 11:17 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio
2015-01-04 15:20 - 2011-01-31 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 8
2015-01-04 15:20 - 2010-12-26 23:25 - 00000000 ____D () C:\Program Files (x86)\EA GAMES
2015-01-04 15:20 - 2010-12-26 23:21 - 00000000 ____D () C:\Program Files (x86)\DAEMON Tools Lite
2015-01-04 15:20 - 2010-12-05 16:19 - 00000000 ____D () C:\Program Files (x86)\Real
2015-01-04 15:20 - 2010-11-07 23:30 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2015-01-04 15:20 - 2010-11-07 11:59 - 00000000 ____D () C:\Program Files (x86)\PC Connectivity Solution
2015-01-04 15:20 - 2010-11-07 11:59 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2015-01-04 15:20 - 2010-11-02 11:09 - 00000000 ____D () C:\Program Files (x86)\Pidgin
2015-01-04 15:20 - 2010-10-11 22:20 - 00000000 ____D () C:\Program Files (x86)\DivX
2015-01-04 15:20 - 2010-10-06 13:57 - 00000000 ____D () C:\Program Files (x86)\Electronic Arts
2015-01-04 15:20 - 2010-10-02 20:47 - 00000000 ____D () C:\Program Files (x86)\QIP 2010
2015-01-04 15:20 - 2010-09-27 20:03 - 00000000 ____D () C:\Program Files (x86)\QIP
2015-01-04 15:20 - 2010-04-08 14:31 - 00000000 ____D () C:\Program Files (x86)\Realtek WLAN Driver
2015-01-04 15:20 - 2010-03-11 12:21 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-01-04 15:20 - 2010-03-11 12:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2015-01-04 15:20 - 2010-03-11 12:04 - 00000000 ____D () C:\Program Files (x86)\Google
2015-01-04 15:20 - 2010-03-11 12:02 - 00000000 ____D () C:\Program Files (x86)\Adobe
2015-01-04 15:20 - 2010-03-11 11:54 - 00000000 ____D () C:\Program Files (x86)\Java
2015-01-04 15:20 - 2010-03-11 11:53 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-04 15:20 - 2010-03-11 11:51 - 00000000 ____D () C:\Program Files (x86)\Intel
2015-01-04 15:20 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2015-01-04 15:20 - 2009-07-14 06:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2015-01-04 11:42 - 2012-03-08 08:12 - 00000512 ____H () C:\Users\admin\Desktop\~$ruhy_ot_zek_k_organick_sti_zkou_ky-1.DOCX.wdfljvj
2015-01-04 10:52 - 2012-03-08 08:12 - 00769776 _____ () C:\Users\admin\Downloads\1_Organick_chemie-1 (2).PDF.wdfljvj
2015-01-04 10:47 - 2014-05-30 13:35 - 00001982 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-01-04 10:47 - 2012-03-08 08:12 - 00042832 _____ () C:\Users\admin\Desktop\1461267_10203731813201884_4525841001195253217_n.JPG.wdfljvj
2015-01-04 10:04 - 2012-03-08 08:12 - 00022112 _____ () C:\Users\admin\Downloads\org reakce.DOCX.wdfljvj
2015-01-04 10:01 - 2012-03-08 08:12 - 00769776 _____ () C:\Users\admin\Downloads\1_Organick_chemie-1 (1).PDF.wdfljvj
2015-01-04 09:30 - 2012-03-08 08:12 - 00769776 _____ () C:\Users\admin\Downloads\1_Organick_chemie-1.PDF.wdfljvj
2015-01-04 09:21 - 2012-03-08 08:12 - 00028000 _____ () C:\Users\admin\Downloads\Okruhy_ot_zek_k_organick_sti_zkou_ky.DOC.wdfljvj
2015-01-04 08:29 - 2013-11-17 13:43 - 00002292 _____ () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-12-22 19:49 - 2012-09-24 11:21 - 00000000 ____D () C:\Users\admin\AppData\Local\Windows Live
2014-12-19 19:00 - 2013-06-05 12:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-12-15 22:16 - 2010-09-04 12:52 - 00111608 _____ () C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-04 19:37
==================== End Of Log ============================