Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by R (administrator) on R-HP on 05-04-2014 23:37:05
Running from C:\Users\R\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: Czech
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
Download link for 64-Bit Version:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\STacSV64.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe
(Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
(Microsoft Corporation) c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Hewlett-Packard ) C:\Program Files\IDT\WDM\beats64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTSched.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.23.9\GoogleCrashHandler64.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BeatsOSDApp] - C:\Program Files\IDT\WDM\beats64.exe [37888 2010-10-21] (Hewlett-Packard )
HKLM\...\Run: [hpsysdrv] - c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [62768 2008-11-20] (Hewlett-Packard)
HKLM-x32\...\Run: [NeroFilterCheck] - C:\Windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-03-25] (Hewlett-Packard)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\Run: [CreativeTaskScheduler] - C:\Program Files (x86)\Creative\Shared Files\CTSched.exe [53341 2006-11-17] (Creative Technology Ltd)
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\Policies\system: [DisableLockWorkstation] 0
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\Policies\system: [DisableChangePassword] 0
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: J - J:\LaunchU3.exe -a
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: K - K:\LaunchU3.exe -a
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: L - L:\LaunchU3.exe -a
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: {73eafd82-3873-11e1-afaa-e06995d0fdb8} - J:\launcher.exe
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: {be5fc397-3096-11e1-987d-e06995d0fdb8} - M:\ZTE_Handset_USB_Driver.exe
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: {dcf14671-d57b-11e0-874d-e06995d0fdb8} - K:\LaunchU3.exe -a
HKU\S-1-5-21-93735815-1299707322-140628041-1000\...\MountPoints2: {ff09786f-eb4b-11e0-80f3-e06995d0fdb8} - J:\INSTALL.EXE
==================== Internet (Whitelisted) ====================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
SearchScopes: HKLM - DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E}
http://ccfiles.creative.com/Web/softwar ... PIDPDE.cab
DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwar ... /CTPID.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter-x32: application/octet-stream - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter-x32: application/x-complus - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
Filter-x32: application/x-msdownload - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll No File
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-08-16] (EasyBits Software Corp.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{A4748267-3642-46B9-BBD0-D6D8B7A0A1FE}: [NameServer]8.8.8.8,8.8.4.4
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\R\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-22]
CHR Extension: (Google Drive) - C:\Users\R\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-22]
CHR Extension: (YouTube) - C:\Users\R\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-22]
CHR Extension: (Google Search) - C:\Users\R\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-22]
CHR Extension: (Gmail) - C:\Users\R\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-22]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Users\R\AppData\Roaming\DVDVideoSoft\dvsYoutubeDownload.crx [2013-05-19]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-03-03]
==================== Services (Whitelisted) =================
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [140672 2012-07-11] (SUPERAntiSpyware.com)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1363584 2014-03-03] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1748608 2014-03-03] (Microsoft Corporation)
S4 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2151200 2013-12-03] (IObit)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
R2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [40999448 2008-07-10] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4390376 2011-07-17] (INCA Internet Co., Ltd.)
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1127448 2011-02-01] (PDF Complete Inc)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75136 2013-09-01] ()
S2 pr2agqwb; C:\Windows\system32\pr2agqwb.exe [777576 2007-11-14] (Cyanide)
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [369688 2008-07-10] (Microsoft Corporation)
R3 WinHttpAutoProxySvc; winhttp.dll [X]
==================== Drivers (Whitelisted) ====================
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [279616 2012-01-07] (DT Soft Ltd)
S3 dump_wmimmc; No ImagePath
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99800 2014-02-26] (Intel Corporation)
S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2004-12-31] (INCA Internet Co., Ltd.)
R0 pe3agqwb; C:\Windows\System32\drivers\pe3agqwb.sys [72296 2007-11-14] (Cyanide)
R0 ps7agqwb; C:\Windows\System32\drivers\ps7agqwb.sys [102000 2007-11-14] (Cyanide)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 UnlockerDriver5; C:\Program Files (x86)\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () <===== ATTENTION Necurs Rootkit?
S3 XENfiltv; C:\Windows\System32\drivers\XENfiltv.sys [25600 2009-07-31] (Creative Technology Ltd.)
S3 cpuz136; \??\C:\Users\R\AppData\Local\Temp\cpuz136\cpuz136_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-05 23:35 - 2014-04-05 23:35 - 05003552 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-05 23:35 - 2014-04-05 23:35 - 00000056 _____ () C:\Windows\setupact.log
2014-04-05 23:35 - 2014-04-05 23:35 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-05 23:30 - 2014-04-05 23:35 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-05 23:25 - 2014-04-05 23:36 - 00000000 ____D () C:\Users\R\Desktop\FRST
2014-04-05 22:56 - 2014-04-05 22:56 - 00044273 _____ () C:\Users\R\Desktop\Addition.txt
2014-04-05 22:46 - 2014-04-05 23:37 - 00011520 _____ () C:\Users\R\Desktop\FRST.txt
2014-04-05 22:45 - 2014-04-05 23:37 - 00000000 ____D () C:\FRST
2014-04-05 22:45 - 2014-04-05 22:45 - 02157056 _____ (Farbar) C:\Users\R\Desktop\FRST64.exe
2014-04-05 22:23 - 2014-04-05 22:23 - 00000000 ____D () C:\_OTL
2014-04-05 22:00 - 2014-04-05 22:00 - 00000000 ____D () C:\Qoobox
2014-04-05 21:59 - 2014-04-05 21:59 - 05193579 ____R (Swearware) C:\Users\R\Desktop\ComboFix.exe
2014-04-05 21:59 - 2014-04-05 21:59 - 00000000 ____D () C:\Windows\erdnt
2014-04-05 21:57 - 2014-04-05 21:58 - 00003172 _____ () C:\Users\R\Desktop\Rkill.txt
2014-04-05 21:57 - 2014-04-05 21:57 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\R\Desktop\rkill.exe
2014-04-05 21:55 - 2014-04-05 21:55 - 00000512 _____ () C:\PhysicalMBR.bin
2014-04-05 21:53 - 2014-04-05 21:53 - 00602112 _____ (OldTimer Tools) C:\Users\R\Desktop\OTL.exe
2014-04-05 21:08 - 2014-04-05 21:08 - 00014465 _____ () C:\Users\R\Desktop\AdwCleaner[R0].txt
2014-04-05 21:04 - 2014-04-05 21:09 - 00000000 ____D () C:\AdwCleaner
2014-04-05 20:54 - 2014-04-05 20:54 - 01426178 _____ () C:\Users\R\Desktop\AdwCleaner.exe
2014-04-05 20:54 - 2014-04-05 20:54 - 01038974 _____ (Thisisu) C:\Users\R\Desktop\JRT.exe
2014-04-05 15:50 - 2014-04-05 16:31 - 736506338 _____ () C:\Users\R\Desktop\Vrána=1994-Akční-DVD-CZ.avi
2014-04-05 01:05 - 2014-04-05 01:05 - 00165888 _____ () C:\Users\R\Documents\T-Cleaner.exe
2014-04-04 22:28 - 2014-04-04 22:41 - 123185915 _____ () C:\Users\R\Desktop\Duch-=1990-Romantický-DVD-CZ.avi
2014-04-04 22:24 - 2014-04-04 22:28 - 21942207 _____ () C:\Users\R\Desktop\Carrie-(2013)-Novinka-CZ-dabing-Drama-Horor-Mysteriozní-výborná-BDRip-kvalita-.MEMRC123..avi
2014-04-04 21:49 - 2014-04-04 22:08 - 351481856 _____ () C:\Users\R\Desktop\Hannah-Montana-1x01---Lilly,-chces-znat-tajemstvi-.avi
2014-04-03 23:43 - 2014-04-03 23:58 - 286788548 _____ () C:\Users\R\Desktop\Lord-Ryolith-HC-3.4.2014.mp4
2014-04-03 21:12 - 2014-04-03 21:53 - 731565116 _____ () C:\Users\R\Desktop\Deník-princezny.CZ-dab.Mikky.avi
2014-04-03 16:21 - 2014-04-03 16:21 - 00000000 _____ () C:\Users\R\Desktop\fl hc.txt
2014-04-02 17:07 - 2014-04-02 17:08 - 00000000 ____D () C:\Users\R\Desktop\Nová složka (3)
2014-04-01 19:07 - 2014-04-01 19:53 - 828302680 _____ () C:\Users\R\Desktop\Farma-smrti-cz-[natu3].avi
2014-04-01 10:37 - 2014-04-01 10:37 - 00009216 _____ () C:\Users\R\Documents\cc_20140401_103749.reg
2014-04-01 10:08 - 2014-04-05 01:07 - 00000000 _____ () C:\SRStatus2.txt
2014-03-31 23:43 - 2014-03-31 23:43 - 00008585 _____ () C:\Users\R\Desktop\mbam.txt
2014-03-31 23:13 - 2014-04-01 10:44 - 00000115 _____ () C:\Users\R\Desktop\Nový textový dokument.txt
2014-03-31 21:35 - 2014-03-31 21:35 - 00001100 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-31 21:35 - 2014-03-31 21:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-31 21:35 - 2014-03-05 09:32 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-31 21:35 - 2014-03-05 09:32 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-31 21:35 - 2014-03-05 09:32 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 21:34 - 2014-03-31 21:34 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\R\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-31 21:32 - 2014-04-05 23:36 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-31 21:31 - 2014-03-31 21:31 - 17523520 _____ (Malwarebytes Corporation ) C:\Users\R\Desktop\mbam-setup.exe
2014-03-31 18:35 - 2014-03-31 19:44 - 1248584811 _____ () C:\Users\R\Desktop\NOVÁ-DCERA-CZ-dabing-Thriller-Horor-(2009)-s-KCostnerom.wmv
2014-03-31 16:59 - 2014-03-31 16:59 - 00000000 _____ () C:\Users\R\Desktop\OSType.txt
2014-03-31 12:27 - 2014-04-05 22:04 - 00000000 ___SD () C:\32788R22FWJFW
2014-03-31 03:22 - 2014-03-31 03:24 - 00000000 ____D () C:\Users\R\Desktop\flashka
2014-03-31 03:19 - 2014-03-31 03:27 - 00000000 ____D () C:\Users\R\Desktop\nova
2014-03-30 21:44 - 2014-03-30 21:44 - 00004450 _____ () C:\Users\test\Desktop\RKreport[0]_D_03302014_214412.txt
2014-03-30 21:43 - 2014-03-30 21:43 - 00004360 _____ () C:\Users\test\Desktop\RKreport[0]_S_03302014_214326.txt
2014-03-30 21:33 - 2014-03-30 21:55 - 00000000 ____D () C:\Users\test\Desktop\RK_Quarantine
2014-03-30 21:30 - 2014-03-30 21:31 - 03972608 _____ () C:\Users\test\Downloads\RogueKiller.exe
2014-03-30 20:19 - 2014-03-30 20:20 - 00000000 ____D () C:\Users\R\Desktop\plocha
2014-03-30 20:17 - 2014-03-30 20:17 - 00004466 _____ () C:\Users\test\Documents\cc_20140330_201736.reg
2014-03-30 17:56 - 2014-03-30 17:56 - 00000000 ____D () C:\Users\test\AppData\Roaming\Malwarebytes
2014-03-30 17:55 - 2014-03-30 17:55 - 00000000 ____D () C:\Users\test\AppData\Roaming\AVAST Software
2014-03-30 17:41 - 2014-03-30 17:58 - 3201380352 _____ () C:\Users\R\AppData\Roaming\tmp.tmp
2014-03-30 17:38 - 2014-03-30 17:38 - 00012999 _____ () C:\Users\R\Documents\hijackthis.log
2014-03-30 16:38 - 2014-03-31 21:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 16:38 - 2014-03-30 19:12 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-30 16:38 - 2014-03-30 16:38 - 00000000 ____D () C:\Users\R\AppData\Roaming\Malwarebytes
2014-03-30 01:40 - 2014-03-30 01:40 - 00000000 ____D () C:\Users\R\AppData\Roaming\AVAST Software
2014-03-30 01:38 - 2014-03-30 01:38 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-29 17:29 - 2014-03-29 19:07 - 833394688 _____ () C:\Users\R\Documents\PAN-DOMU---CZ-dvdrip.avi
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\Users\R\AppData\Local\VS Revo Group
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\ProgramData\VS Revo Group
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-29 05:36 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2014-03-29 05:33 - 2014-03-29 05:33 - 00000000 ____D () C:\Users\R\AppData\Roaming\Flashmedia
2014-03-29 02:03 - 2014-03-29 02:03 - 00002525 _____ () C:\Users\R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DC Universe Online.lnk
2014-03-27 17:05 - 2014-04-03 17:09 - 00000000 ____D () C:\Users\R\Desktop\Nová složka (2)
2014-03-19 22:21 - 2014-03-19 22:21 - 02815713 _____ () C:\Users\R\Documents\Bez názvu.wma
2014-03-19 16:30 - 2014-03-19 16:30 - 00000000 ____D () C:\ProgramData\Steam
2014-03-19 16:07 - 2014-03-19 16:07 - 00000000 ____D () C:\Program Files (x86)\Total War Rome II CZ
2014-03-17 05:46 - 2014-03-17 05:46 - 00000000 ____D () C:\Users\R\Documents\LucasArts
2014-03-17 05:46 - 2014-03-17 05:46 - 00000000 ____D () C:\Users\R\AppData\Local\LucasArts
2014-03-17 01:27 - 2014-03-17 01:27 - 00000000 ____D () C:\Program Files (x86)\LucasArts
2014-03-17 00:44 - 2014-04-04 21:39 - 00000000 ____D () C:\Users\R\Desktop\afsafs
2014-03-16 20:16 - 2014-03-16 20:17 - 00000000 ____D () C:\Users\R\Desktop\Maturitní ples 2POA
2014-03-16 18:29 - 2014-03-16 18:35 - 736757760 _____ () C:\Users\R\Documents\KOPACKY-2008-KOMEDIE-CZ-DABING.avi
2014-03-16 15:32 - 2014-03-16 15:37 - 774180380 _____ () C:\Users\R\Documents\Silent-Hill-2006.CZ-dab.avi
2014-03-13 06:01 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 06:01 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 06:01 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 06:01 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 06:01 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 06:01 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 06:01 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 06:01 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 06:01 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 06:01 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 06:01 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 06:01 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 06:01 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-13 06:01 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 06:01 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 06:01 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-13 06:01 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 06:01 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 06:01 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-13 06:01 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-13 06:01 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-13 06:01 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-13 06:01 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-13 06:01 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 06:01 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-13 06:01 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-13 06:01 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-13 06:01 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 06:01 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 06:01 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-13 06:01 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-13 06:01 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 06:01 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-13 06:01 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-13 06:01 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-13 06:01 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 06:01 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-13 06:01 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-13 06:01 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 06:01 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-13 06:01 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 06:01 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 06:01 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-13 06:01 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-13 06:00 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 06:00 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 06:00 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-13 06:00 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-09 23:04 - 2014-03-09 23:04 - 00044752 _____ () C:\Users\R\Downloads\stažený soubor (4).htm
2014-03-09 22:48 - 2014-03-09 22:48 - 00044518 _____ () C:\Users\R\Downloads\stažený soubor (3).htm
2014-03-09 22:48 - 2014-03-09 22:48 - 00044518 _____ () C:\Users\R\Downloads\stažený soubor (2).htm
2014-03-09 22:43 - 2014-03-09 22:43 - 00058450 _____ () C:\Users\R\Downloads\viewforum (4).htm
2014-03-09 22:34 - 2014-03-09 22:34 - 00031929 _____ () C:\Users\R\Downloads\stažený soubor (1).htm
2014-03-09 22:34 - 2014-03-09 22:34 - 00013767 _____ () C:\Users\R\Downloads\forum (1).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00031070 _____ () C:\Users\R\Downloads\viewforum.htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (3).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (2).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (1).htm
2014-03-09 16:06 - 2014-03-09 16:06 - 00042188 _____ () C:\Users\R\Downloads\stažený soubor.htm
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (6).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (5).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (4).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (3).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (2).php
2014-03-09 14:03 - 2014-03-09 14:03 - 00041975 _____ () C:\Users\R\Downloads\index.php
2014-03-09 14:03 - 2014-03-09 14:03 - 00041975 _____ () C:\Users\R\Downloads\index (1).php
2014-03-09 01:16 - 2014-03-09 01:16 - 00956137 _____ () C:\Users\R\Downloads\pc_budik_2012.zip
2014-03-09 01:16 - 2014-03-09 01:16 - 00956137 _____ () C:\Users\R\Downloads\pc_budik_2012 (1).zip
2014-03-07 12:38 - 2014-03-07 12:38 - 00048406 _____ () C:\Users\R\Downloads\viewtopic (1).htm
2014-03-06 20:43 - 2014-03-06 20:43 - 00042627 _____ () C:\Users\R\Downloads\viewtopic.htm
2014-03-06 19:26 - 2014-03-06 19:26 - 00013767 _____ () C:\Users\R\Downloads\forum.htm
==================== One Month Modified Files and Folders =======
2014-04-05 23:37 - 2014-04-05 22:46 - 00011520 _____ () C:\Users\R\Desktop\FRST.txt
2014-04-05 23:37 - 2014-04-05 22:45 - 00000000 ____D () C:\FRST
2014-04-05 23:36 - 2014-04-05 23:25 - 00000000 ____D () C:\Users\R\Desktop\FRST
2014-04-05 23:36 - 2014-03-31 21:32 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-05 23:36 - 2011-09-19 02:00 - 00000938 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-05 23:36 - 2011-08-16 13:32 - 00000000 ____D () C:\ProgramData\PDFC
2014-04-05 23:35 - 2014-04-05 23:35 - 05003552 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-05 23:35 - 2014-04-05 23:35 - 00000056 _____ () C:\Windows\setupact.log
2014-04-05 23:35 - 2014-04-05 23:35 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-05 23:35 - 2014-04-05 23:30 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-05 23:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-05 23:35 - 2009-07-14 06:45 - 00024608 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-05 23:32 - 2011-08-16 13:04 - 00737120 _____ () C:\Windows\system32\perfh005.dat
2014-04-05 23:32 - 2011-08-16 13:04 - 00166810 _____ () C:\Windows\system32\perfc005.dat
2014-04-05 23:32 - 2009-07-14 07:13 - 01775876 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-05 23:26 - 2013-06-03 22:15 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-04-05 23:26 - 2011-09-19 02:00 - 00000942 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-05 23:24 - 2012-04-16 19:11 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-05 23:24 - 2012-04-16 19:11 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy
2014-04-05 22:56 - 2014-04-05 22:56 - 00044273 _____ () C:\Users\R\Desktop\Addition.txt
2014-04-05 22:45 - 2014-04-05 22:45 - 02157056 _____ (Farbar) C:\Users\R\Desktop\FRST64.exe
2014-04-05 22:39 - 2012-06-25 10:10 - 00000914 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 22:26 - 2011-09-02 18:09 - 00000000 ____D () C:\Users\R\AppData\Roaming\Skype
2014-04-05 22:23 - 2014-04-05 22:23 - 00000000 ____D () C:\_OTL
2014-04-05 22:23 - 2013-05-30 12:23 - 00000000 ___RD () C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-05 22:23 - 2011-09-02 18:03 - 00000000 ___RD () C:\Users\R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-05 22:04 - 2014-03-31 12:27 - 00000000 ___SD () C:\32788R22FWJFW
2014-04-05 22:00 - 2014-04-05 22:00 - 00000000 ____D () C:\Qoobox
2014-04-05 21:59 - 2014-04-05 21:59 - 05193579 ____R (Swearware) C:\Users\R\Desktop\ComboFix.exe
2014-04-05 21:59 - 2014-04-05 21:59 - 00000000 ____D () C:\Windows\erdnt
2014-04-05 21:58 - 2014-04-05 21:57 - 00003172 _____ () C:\Users\R\Desktop\Rkill.txt
2014-04-05 21:57 - 2014-04-05 21:57 - 01933048 _____ (Bleeping Computer, LLC) C:\Users\R\Desktop\rkill.exe
2014-04-05 21:55 - 2014-04-05 21:55 - 00000512 _____ () C:\PhysicalMBR.bin
2014-04-05 21:53 - 2014-04-05 21:53 - 00602112 _____ (OldTimer Tools) C:\Users\R\Desktop\OTL.exe
2014-04-05 21:09 - 2014-04-05 21:04 - 00000000 ____D () C:\AdwCleaner
2014-04-05 21:09 - 2012-08-15 23:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-05 21:09 - 2011-11-17 17:52 - 00000000 ____D () C:\ProgramData\ICQ
2014-04-05 21:08 - 2014-04-05 21:08 - 00014465 _____ () C:\Users\R\Desktop\AdwCleaner[R0].txt
2014-04-05 20:54 - 2014-04-05 20:54 - 01426178 _____ () C:\Users\R\Desktop\AdwCleaner.exe
2014-04-05 20:54 - 2014-04-05 20:54 - 01038974 _____ (Thisisu) C:\Users\R\Desktop\JRT.exe
2014-04-05 18:27 - 2011-09-09 23:44 - 00000000 ____D () C:\Users\R\AppData\Roaming\TS3Client
2014-04-05 16:31 - 2014-04-05 15:50 - 736506338 _____ () C:\Users\R\Desktop\Vrána=1994-Akční-DVD-CZ.avi
2014-04-05 01:16 - 2014-03-01 19:11 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-05 01:09 - 2011-09-21 00:53 - 00000000 ____D () C:\Users\R\AppData\Roaming\Media Player Classic
2014-04-05 01:07 - 2014-04-01 10:08 - 00000000 _____ () C:\SRStatus2.txt
2014-04-05 01:07 - 2011-09-02 17:55 - 00000000 ____D () C:\Users\R
2014-04-05 01:05 - 2014-04-05 01:05 - 00165888 _____ () C:\Users\R\Documents\T-Cleaner.exe
2014-04-05 01:05 - 2012-12-30 17:36 - 00000000 ____D () C:\Users\R\Documents\The KMPlayer
2014-04-04 22:41 - 2014-04-04 22:28 - 123185915 _____ () C:\Users\R\Desktop\Duch-=1990-Romantický-DVD-CZ.avi
2014-04-04 22:28 - 2014-04-04 22:24 - 21942207 _____ () C:\Users\R\Desktop\Carrie-(2013)-Novinka-CZ-dabing-Drama-Horor-Mysteriozní-výborná-BDRip-kvalita-.MEMRC123..avi
2014-04-04 22:08 - 2014-04-04 21:49 - 351481856 _____ () C:\Users\R\Desktop\Hannah-Montana-1x01---Lilly,-chces-znat-tajemstvi-.avi
2014-04-04 21:39 - 2014-03-17 00:44 - 00000000 ____D () C:\Users\R\Desktop\afsafs
2014-04-04 18:32 - 2012-11-10 09:54 - 00000316 _____ () C:\Windows\Tasks\HPCeeScheduleForR.job
2014-04-04 02:45 - 2012-11-10 09:54 - 00003162 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForR
2014-04-04 02:45 - 2011-11-05 15:04 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-04-04 02:45 - 2011-09-10 09:40 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-04-04 02:44 - 2011-09-10 09:33 - 00000000 ____D () C:\Users\R\AppData\Roaming\HP Support Assistant
2014-04-04 02:44 - 2011-09-03 20:41 - 00000000 ____D () C:\Users\R\AppData\Roaming\HpUpdate
2014-04-03 23:58 - 2014-04-03 23:43 - 286788548 _____ () C:\Users\R\Desktop\Lord-Ryolith-HC-3.4.2014.mp4
2014-04-03 21:53 - 2014-04-03 21:12 - 731565116 _____ () C:\Users\R\Desktop\Deník-princezny.CZ-dab.Mikky.avi
2014-04-03 17:17 - 2013-09-22 23:39 - 00000000 ____D () C:\Users\R\AppData\Roaming\Spotify
2014-04-03 17:09 - 2014-03-27 17:05 - 00000000 ____D () C:\Users\R\Desktop\Nová složka (2)
2014-04-03 16:21 - 2014-04-03 16:21 - 00000000 _____ () C:\Users\R\Desktop\fl hc.txt
2014-04-02 17:08 - 2014-04-02 17:07 - 00000000 ____D () C:\Users\R\Desktop\Nová složka (3)
2014-04-02 01:29 - 2013-09-22 23:40 - 00000000 ____D () C:\Users\R\AppData\Local\Spotify
2014-04-01 19:53 - 2014-04-01 19:07 - 828302680 _____ () C:\Users\R\Desktop\Farma-smrti-cz-[natu3].avi
2014-04-01 10:44 - 2014-03-31 23:13 - 00000115 _____ () C:\Users\R\Desktop\Nový textový dokument.txt
2014-04-01 10:37 - 2014-04-01 10:37 - 00009216 _____ () C:\Users\R\Documents\cc_20140401_103749.reg
2014-03-31 23:43 - 2014-03-31 23:43 - 00008585 _____ () C:\Users\R\Desktop\mbam.txt
2014-03-31 21:35 - 2014-03-31 21:35 - 00001100 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-31 21:35 - 2014-03-31 21:35 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-31 21:34 - 2014-03-31 21:34 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\R\Desktop\mbam-setup-1.75.0.1300.exe
2014-03-31 21:32 - 2014-03-30 16:38 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-31 21:31 - 2014-03-31 21:31 - 17523520 _____ (Malwarebytes Corporation ) C:\Users\R\Desktop\mbam-setup.exe
2014-03-31 19:44 - 2014-03-31 18:35 - 1248584811 _____ () C:\Users\R\Desktop\NOVÁ-DCERA-CZ-dabing-Thriller-Horor-(2009)-s-KCostnerom.wmv
2014-03-31 16:59 - 2014-03-31 16:59 - 00000000 _____ () C:\Users\R\Desktop\OSType.txt
2014-03-31 03:27 - 2014-03-31 03:19 - 00000000 ____D () C:\Users\R\Desktop\nova
2014-03-31 03:24 - 2014-03-31 03:22 - 00000000 ____D () C:\Users\R\Desktop\flashka
2014-03-31 03:18 - 2011-09-03 22:06 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-30 22:19 - 2013-04-04 19:22 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-03-30 21:58 - 2014-02-28 22:05 - 00000000 ____D () C:\Users\test\AppData\Roaming\TS3Client
2014-03-30 21:55 - 2014-03-30 21:33 - 00000000 ____D () C:\Users\test\Desktop\RK_Quarantine
2014-03-30 21:44 - 2014-03-30 21:44 - 00004450 _____ () C:\Users\test\Desktop\RKreport[0]_D_03302014_214412.txt
2014-03-30 21:43 - 2014-03-30 21:43 - 00004360 _____ () C:\Users\test\Desktop\RKreport[0]_S_03302014_214326.txt
2014-03-30 21:31 - 2014-03-30 21:30 - 03972608 _____ () C:\Users\test\Downloads\RogueKiller.exe
2014-03-30 21:00 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-30 20:20 - 2014-03-30 20:19 - 00000000 ____D () C:\Users\R\Desktop\plocha
2014-03-30 20:17 - 2014-03-30 20:17 - 00004466 _____ () C:\Users\test\Documents\cc_20140330_201736.reg
2014-03-30 19:38 - 2013-06-04 09:01 - 00000000 ____D () C:\Users\Guest
2014-03-30 19:38 - 2013-05-30 12:23 - 00000000 ____D () C:\Users\test
2014-03-30 19:37 - 2014-02-28 19:49 - 00000000 ____D () C:\Users\test\AppData\Local\Google
2014-03-30 19:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-03-30 19:12 - 2014-03-30 16:38 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-03-30 18:34 - 2013-05-30 12:23 - 00000000 ____D () C:\Users\test\AppData\Local\VirtualStore
2014-03-30 17:58 - 2014-03-30 17:41 - 3201380352 _____ () C:\Users\R\AppData\Roaming\tmp.tmp
2014-03-30 17:56 - 2014-03-30 17:56 - 00000000 ____D () C:\Users\test\AppData\Roaming\Malwarebytes
2014-03-30 17:55 - 2014-03-30 17:55 - 00000000 ____D () C:\Users\test\AppData\Roaming\AVAST Software
2014-03-30 17:38 - 2014-03-30 17:38 - 00012999 _____ () C:\Users\R\Documents\hijackthis.log
2014-03-30 16:38 - 2014-03-30 16:38 - 00000000 ____D () C:\Users\R\AppData\Roaming\Malwarebytes
2014-03-30 01:40 - 2014-03-30 01:40 - 00000000 ____D () C:\Users\R\AppData\Roaming\AVAST Software
2014-03-30 01:38 - 2014-03-30 01:38 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-30 01:36 - 2014-01-03 04:10 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-29 19:07 - 2014-03-29 17:29 - 833394688 _____ () C:\Users\R\Documents\PAN-DOMU---CZ-dvdrip.avi
2014-03-29 12:21 - 2011-09-19 02:00 - 00003938 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 12:21 - 2011-09-19 02:00 - 00003686 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-29 06:26 - 2012-09-20 21:31 - 00000000 ____D () C:\Program Files (x86)\DesetiPrsty
2014-03-29 06:21 - 2011-09-30 17:55 - 00000000 ____D () C:\Users\R\AppData\Roaming\DAEMON Tools Lite
2014-03-29 06:15 - 2011-11-14 01:48 - 00000000 ____D () C:\Program Files\DivX
2014-03-29 06:15 - 2011-11-14 01:47 - 00000000 ____D () C:\ProgramData\DivX
2014-03-29 06:15 - 2011-11-14 01:47 - 00000000 ____D () C:\Program Files (x86)\DivX
2014-03-29 06:11 - 2012-03-23 21:37 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-03-29 06:05 - 2012-05-12 20:40 - 00000000 ____D () C:\Users\R\AppData\Roaming\Groovedown
2014-03-29 06:04 - 2012-06-07 12:54 - 00000000 ____D () C:\Users\R\AppData\Roaming\Xilisoft
2014-03-29 06:03 - 2012-06-17 12:28 - 00000000 ____D () C:\Program Files (x86)\URUSoft
2014-03-29 05:59 - 2012-12-22 21:02 - 00000000 ____D () C:\Program Files (x86)\SpeedFan
2014-03-29 05:57 - 2011-09-02 21:31 - 00000000 ____D () C:\Users\R\AppData\Roaming\Ubisoft
2014-03-29 05:57 - 2011-08-16 13:20 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-03-29 05:38 - 2012-10-02 00:15 - 00007589 _____ () C:\Users\R\AppData\Local\resmon.resmoncfg
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\Users\R\AppData\Local\VS Revo Group
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\ProgramData\VS Revo Group
2014-03-29 05:36 - 2014-03-29 05:36 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-29 05:33 - 2014-03-29 05:33 - 00000000 ____D () C:\Users\R\AppData\Roaming\Flashmedia
2014-03-29 05:12 - 2013-02-24 15:32 - 00000000 ____D () C:\Users\R\AppData\Roaming\BitTorrent
2014-03-29 05:11 - 2013-03-10 19:53 - 00000000 ____D () C:\Program Files (x86)\JAM Software
2014-03-29 04:50 - 2013-03-21 22:30 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-03-29 03:34 - 2011-09-26 15:50 - 00000000 ____D () C:\Program Files (x86)\IObit
2014-03-29 02:03 - 2014-03-29 02:03 - 00002525 _____ () C:\Users\R\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DC Universe Online.lnk
2014-03-29 02:03 - 2011-11-27 21:59 - 00000000 ____D () C:\Windows\SysWOW64\directx
2014-03-23 04:04 - 2013-12-20 16:34 - 00000000 ____D () C:\Users\R\AppData\Local\Battle.net
2014-03-23 02:51 - 2013-12-20 16:36 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-23 02:48 - 2013-12-20 16:34 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-19 22:21 - 2014-03-19 22:21 - 02815713 _____ () C:\Users\R\Documents\Bez názvu.wma
2014-03-19 16:30 - 2014-03-19 16:30 - 00000000 ____D () C:\ProgramData\Steam
2014-03-19 16:07 - 2014-03-19 16:07 - 00000000 ____D () C:\Program Files (x86)\Total War Rome II CZ
2014-03-19 03:04 - 2013-07-12 06:44 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 03:00 - 2011-09-04 18:58 - 90015360 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-17 20:05 - 2014-03-01 02:39 - 00000000 ____D () C:\Users\test\AppData\Local\CrashDumps
2014-03-17 05:46 - 2014-03-17 05:46 - 00000000 ____D () C:\Users\R\Documents\LucasArts
2014-03-17 05:46 - 2014-03-17 05:46 - 00000000 ____D () C:\Users\R\AppData\Local\LucasArts
2014-03-17 01:27 - 2014-03-17 01:27 - 00000000 ____D () C:\Program Files (x86)\LucasArts
2014-03-16 20:17 - 2014-03-16 20:16 - 00000000 ____D () C:\Users\R\Desktop\Maturitní ples 2POA
2014-03-16 19:40 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-16 18:35 - 2014-03-16 18:29 - 736757760 _____ () C:\Users\R\Documents\KOPACKY-2008-KOMEDIE-CZ-DABING.avi
2014-03-16 15:37 - 2014-03-16 15:32 - 774180380 _____ () C:\Users\R\Documents\Silent-Hill-2006.CZ-dab.avi
2014-03-15 16:47 - 2013-03-10 17:43 - 00000000 ____D () C:\Windows\Minidump
2014-03-15 10:47 - 2009-07-14 07:08 - 00032586 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-14 23:06 - 2011-09-05 22:42 - 00000000 ____D () C:\Users\R\AppData\Local\CrashDumps
2014-03-13 19:16 - 2011-09-02 18:09 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-12 05:41 - 2011-08-16 13:24 - 00000000 ____D () C:\Program Files (x86)\Microsoft Office
2014-03-12 05:39 - 2011-11-02 01:44 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-03-12 05:39 - 2010-11-21 09:16 - 00000000 ____D () C:\Windows\ShellNew
2014-03-12 05:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-03-11 22:39 - 2012-06-25 10:10 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-11 22:39 - 2012-06-25 10:10 - 00003852 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-11 22:39 - 2011-12-18 13:57 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-09 23:04 - 2014-03-09 23:04 - 00044752 _____ () C:\Users\R\Downloads\stažený soubor (4).htm
2014-03-09 22:48 - 2014-03-09 22:48 - 00044518 _____ () C:\Users\R\Downloads\stažený soubor (3).htm
2014-03-09 22:48 - 2014-03-09 22:48 - 00044518 _____ () C:\Users\R\Downloads\stažený soubor (2).htm
2014-03-09 22:43 - 2014-03-09 22:43 - 00058450 _____ () C:\Users\R\Downloads\viewforum (4).htm
2014-03-09 22:34 - 2014-03-09 22:34 - 00031929 _____ () C:\Users\R\Downloads\stažený soubor (1).htm
2014-03-09 22:34 - 2014-03-09 22:34 - 00013767 _____ () C:\Users\R\Downloads\forum (1).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00031070 _____ () C:\Users\R\Downloads\viewforum.htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (3).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (2).htm
2014-03-09 21:45 - 2014-03-09 21:45 - 00025344 _____ () C:\Users\R\Downloads\viewforum (1).htm
2014-03-09 16:06 - 2014-03-09 16:06 - 00042188 _____ () C:\Users\R\Downloads\stažený soubor.htm
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (6).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (5).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (4).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (3).php
2014-03-09 14:06 - 2014-03-09 14:06 - 00042553 _____ () C:\Users\R\Downloads\index (2).php
2014-03-09 14:03 - 2014-03-09 14:03 - 00041975 _____ () C:\Users\R\Downloads\index.php
2014-03-09 14:03 - 2014-03-09 14:03 - 00041975 _____ () C:\Users\R\Downloads\index (1).php
2014-03-09 01:16 - 2014-03-09 01:16 - 00956137 _____ () C:\Users\R\Downloads\pc_budik_2012.zip
2014-03-09 01:16 - 2014-03-09 01:16 - 00956137 _____ () C:\Users\R\Downloads\pc_budik_2012 (1).zip
2014-03-07 12:38 - 2014-03-07 12:38 - 00048406 _____ () C:\Users\R\Downloads\viewtopic (1).htm
2014-03-06 20:43 - 2014-03-06 20:43 - 00042627 _____ () C:\Users\R\Downloads\viewtopic.htm
2014-03-06 19:26 - 2014-03-06 19:26 - 00013767 _____ () C:\Users\R\Downloads\forum.htm
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 05:46
==================== End Of Log ============================