Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2013
Ran by SYSTEM on 07-05-2013 21:29:05
Running from H:\
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Recovery
The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe [595816 2010-04-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38304 2010-07-09] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe [1050072 2010-05-11] (Toshiba Europe GmbH)
HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s [11101800 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /FORPCEE3 [2120808 2010-07-28] (Realtek Semiconductor)
HKLM\...\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE [505768 2010-05-25] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe [570680 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe [915320 2010-05-10] (TOSHIBA Corporation)
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe [238080 2009-10-19] (TOSHIBA Corporation)
HKLM\...\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [709976 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaReminder.exe [136136 2010-04-19] (Toshiba Europe GmbH)
HKLM\...\Run: [M-Audio Taskbar Icon] C:\Windows\system32\M-AudioTaskBarIcon.exe [798728 2010-12-07] (Avid Technology, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [499608 2011-03-15] (Adobe Systems Incorporated)
HKLM\...\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice [6330568 2013-03-04] (ESET)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [35760 2009-12-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe" /WinStart [1086760 2010-03-09] (Nero AG)
HKLM-x32\...\Run: [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume [439568 2010-05-10] (Microsoft Corporation)
HKLM-x32\...\Run: [SVPWUTIL] C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL [352256 2010-02-22] (TOSHIBA)
HKLM-x32\...\Run: [KeNotify] "C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe" LPCM [34160 2010-08-15] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START [83336 2009-07-22] (TOSHIBA CORPORATION)
HKLM-x32\...\Run: [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun [2454840 2010-05-01] (TOSHIBA CORPORATION.)
HKLM-x32\...\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60 [1294136 2009-10-06] (TOSHIBA Corporation)
HKLM-x32\...\Run: [NPSStartup] [x]
HKLM-x32\...\Run: [DigidesignMMERefresh] C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKU\Default\...\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\Default User\...\Run: [TOSHIBA Online Product Information] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\ZS022\...\Run: [PC Suite Tray] "C:\Program Files (x86)\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray [1483264 2010-12-21] (Nokia)
HKU\ZS022\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3672384 2012-04-11] (DT Soft Ltd)
HKU\ZS022\...\Run: [T-Mobile Communication Centre] "C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\Manager.exe" -autorun [1363984 2011-11-22] (Gemfor s.r.o.)
HKU\ZS022\...\Run: [Spotify Web Helper] "C:\Users\ZS022\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1199576 2012-12-19] (Spotify Ltd)
HKU\ZS022\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [18642024 2013-02-28] (Skype Technologies S.A.)
HKU\ZS022\...\Winlogon: [Shell] explorer.exe,C:\Users\ZS022\AppData\Roaming\skype.dat [98304 2011-11-17] () <==== ATTENTION
Startup: C:\ProgramData\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth Manager.lnk
ShortcutTarget: Bluetooth Manager.lnk -> C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
==================== Services (Whitelisted) =================
S2 ameisvc; C:\Program Files (x86)\T-Mobile\Web'n'walk Manager\ameisvc.exe [123120 2011-06-24] (Gemfor s.r.o.)
S2 DigiRefresh; C:\Program Files (x86)\Digidesign\Drivers\MMERefresh.exe [77824 2010-06-24] (Avid Technology, Inc..)
S2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [1341664 2013-03-04] (ESET)
S2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [1811456 2010-08-27] (Realsil Microelectronics Inc.)
S2 MIDISPORTAudioDevMon; C:\Program Files (x86)\M-Audio\MIDISPORT\AudioDevMon.exe [1636872 2010-10-06] (M-Audio)
S3 TemproMonitoringService; C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)
==================== Drivers (Whitelisted) ====================
S3 a4djavs; C:\Windows\System32\Drivers\a4djavs.sys [358480 2012-02-22] (Native Instruments GmbH)
S3 a4djusb_svc; C:\Windows\System32\Drivers\a4djusb.sys [97360 2012-02-22] (Native Instruments GmbH)
S1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-04-28] (DT Soft Ltd)
S1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET)
S1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET)
S2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [139768 2013-01-10] (ESET)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [218624 2011-09-09] (Huawei Technologies Co., Ltd.)
S3 MAUSBFASTTRACK; C:\Windows\System32\DRIVERS\MAudioFastTrack.sys [187912 2010-12-07] (Avid Technology, Inc.)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [862704 2012-04-28] (Duplex Secure Ltd.)
S3 TFsExDisk; \??\C:\Windows\System32\Drivers\TFsExDisk.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-05-07 21:28 - 2013-05-07 21:28 - 00000000 ____D C:\FRST
2013-05-06 12:40 - 2013-05-06 12:40 - 00000000 ____D C:\$WINDOWS.~BT
2013-05-06 12:17 - 2013-05-06 12:17 - 268435456 __ASH C:\WinPEpge.sys
2013-05-04 14:56 - 2013-05-04 14:51 - 00628743 ____A C:\Users\ZS022\Desktop\adwcleaner.exe
2013-05-04 01:23 - 2013-05-06 11:13 - 00000004 ____A C:\Users\ZS022\AppData\Roaming\skype.ini
2013-05-03 18:24 - 2013-05-03 18:31 - 248774454 ____A C:\Users\ZS022\Downloads\Greys.Anatomy.S09E22.HDTV.x264-LOL.mp4
2013-04-30 11:46 - 2013-04-30 11:49 - 173500023 ____A C:\Users\ZS022\Downloads\How.I.Met.Your.Mother.S08E22.HDTV.x264-LOL.mp4
2013-04-29 21:11 - 2013-04-29 21:11 - 00078313 ____A C:\Users\ZS022\Downloads\model rustu prezentace.pptx
2013-04-29 18:16 - 2013-04-29 18:22 - 214040111 ____A C:\Users\ZS022\Downloads\Greys.Anatomy.S09E21.HDTV.x264-LOL.mp4
2013-04-27 13:28 - 2013-04-27 13:28 - 00278224 ____A C:\Windows\Minidump\042713-21216-01.dmp
2013-04-25 20:02 - 2013-04-25 20:15 - 734777344 ____A C:\Users\ZS022\Downloads\The.Prestige.2006.DvDrip.Eng-aXXo.(
www.USABIT.com).avi
2013-04-25 07:31 - 2013-04-25 07:31 - 03891540 ____A C:\Users\ZS022\Downloads\Nippert_Karel-in_out_podk (1).rar
2013-04-24 22:49 - 2013-04-24 22:49 - 03891540 ____A C:\Users\ZS022\Downloads\Nippert_Karel-in_out_podk.rar
2013-04-24 08:50 - 2013-04-12 15:45 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-04-20 17:57 - 2013-04-20 18:06 - 00000000 ____D C:\Users\ZS022\Downloads\Submarine 2011 DVDRip Xvid UnKnOwN
2013-04-19 20:23 - 2013-04-19 20:24 - 00000000 ____D C:\Users\ZS022\Downloads\Shame.2011.LIMITED.DVDRip.XviD-AMIABLE
2013-04-19 07:33 - 2012-04-06 18:33 - 00000000 ____D C:\Users\ZS022\Desktop\CD1
2013-04-18 22:32 - 2013-04-18 23:05 - 582048542 ____A C:\Users\ZS022\Downloads\Duna-audiokniha---cte-Igor-Smrzik-1993-(Herbert-Frank-audiobook)-CD1.zip
2013-04-18 20:09 - 2013-04-18 20:09 - 00000000 ____D C:\Users\ZS022\Downloads\SILVER LININGS DVDRIP EDAW2013
2013-04-18 20:07 - 2013-04-18 20:09 - 00000000 ____D C:\Users\ZS022\Downloads\The.Mist[2007]DvDrip[Eng]-aXXo
2013-04-18 20:01 - 2013-04-18 20:33 - 00000000 ____D C:\Users\ZS022\Downloads\Silver Linings Playbook (2012) [1080p]
2013-04-17 19:44 - 2013-04-17 20:35 - 00000000 ____D C:\Users\ZS022\Downloads\V for Vendetta (2006) [1080p]
2013-04-16 20:42 - 2013-04-16 20:42 - 00071847 ____A C:\Users\ZS022\Downloads\Donnie-Darko(0000178790).srt
2013-04-16 19:38 - 2013-04-16 19:39 - 00000000 ____D C:\Users\ZS022\Downloads\Donnie Darko DIRECTORS CUT (2001) [1080p]
2013-04-16 12:02 - 2013-04-16 12:10 - 178269063 ____A C:\Users\ZS022\Downloads\How.I.Met.Your.Mother.S08E21.HDTV.x264-LOL.mp4
2013-04-14 12:06 - 2013-04-14 12:06 - 00558738 ____A C:\Users\ZS022\Downloads\Bez názvu 2.psd
2013-04-13 14:44 - 2013-04-13 14:44 - 00109609 ____A C:\Users\ZS022\Downloads\levibrush.zip
2013-04-11 09:29 - 2013-04-11 09:28 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-04-11 09:29 - 2013-04-11 09:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-04-11 09:29 - 2013-04-11 09:28 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-04-11 09:23 - 2013-04-11 09:24 - 00896928 ____A (Oracle Corporation) C:\Users\ZS022\Downloads\chromeinstall-7u17.exe
2013-04-10 12:26 - 2013-04-10 12:26 - 03919253 ____A C:\Users\ZS022\Downloads\vecurek.rar
2013-04-10 08:40 - 2013-04-10 08:40 - 04553504 ____A C:\Users\ZS022\Downloads\Petru_Vaclav-Vaclav_Petru_in__out.rar
2013-04-10 08:38 - 2013-03-19 07:04 - 05550424 ____A (Microsoft Corporation) C:\Windows\System32\ntoskrnl.exe
2013-04-10 08:38 - 2013-03-19 06:46 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\csrsrv.dll
2013-04-10 08:38 - 2013-03-19 06:04 - 03968856 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-04-10 08:38 - 2013-03-19 06:04 - 03913560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-04-10 08:38 - 2013-03-19 05:47 - 00006656 ____A (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2013-04-10 08:38 - 2013-03-19 04:06 - 00112640 ____A (Microsoft Corporation) C:\Windows\System32\smss.exe
2013-04-10 08:38 - 2013-03-02 06:56 - 01188864 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-04-10 08:38 - 2013-03-02 06:55 - 01492992 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-04-10 08:38 - 2013-03-02 06:55 - 00134144 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2013-04-10 08:38 - 2013-03-02 06:50 - 09059328 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-04-10 08:38 - 2013-03-02 06:50 - 00735232 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-04-10 08:38 - 2013-03-02 06:50 - 00097792 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-04-10 08:38 - 2013-03-02 06:49 - 12294656 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-04-10 08:38 - 2013-03-02 06:49 - 02458112 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-04-10 08:38 - 2013-03-02 06:49 - 00247808 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-04-10 08:38 - 2013-03-02 06:49 - 00064512 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-04-10 08:38 - 2013-03-02 05:58 - 01231872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-04-10 08:38 - 2013-03-02 05:58 - 00981504 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-04-10 08:38 - 2013-03-02 05:58 - 00132096 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2013-04-10 08:38 - 2013-03-02 05:54 - 06032384 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-04-10 08:38 - 2013-03-02 05:54 - 00627712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-04-10 08:38 - 2013-03-02 05:54 - 00067584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2013-04-10 08:38 - 2013-03-02 05:53 - 00048128 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-04-10 08:38 - 2013-03-02 05:52 - 11020800 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-04-10 08:38 - 2013-03-02 05:52 - 02078208 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-04-10 08:38 - 2013-03-02 05:52 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-04-10 08:38 - 2013-03-02 04:57 - 01638912 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-04-10 08:38 - 2013-03-02 04:22 - 01638912 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-04-10 08:38 - 2013-03-01 04:36 - 03153408 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-04-10 08:38 - 2013-02-15 07:08 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-04-10 08:38 - 2013-02-15 07:06 - 03717632 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-04-10 08:38 - 2013-02-15 07:02 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-04-10 08:38 - 2013-02-15 05:37 - 03217408 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-04-10 08:38 - 2013-02-15 05:34 - 00131584 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-04-10 08:38 - 2013-02-15 04:25 - 00036864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-04-10 08:38 - 2013-01-24 07:01 - 00223752 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\fvevol.sys
==================== One Month Modified Files and Folders =======
2013-05-07 21:28 - 2013-05-07 21:28 - 00000000 ____D C:\FRST
2013-05-07 20:13 - 2009-07-14 06:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-05-07 20:12 - 2009-07-14 05:51 - 00230715 ____A C:\Windows\setupact.log
2013-05-06 12:40 - 2013-05-06 12:40 - 00000000 ____D C:\$WINDOWS.~BT
2013-05-06 12:17 - 2013-05-06 12:17 - 268435456 __ASH C:\WinPEpge.sys
2013-05-06 11:13 - 2013-05-04 01:23 - 00000004 ____A C:\Users\ZS022\AppData\Roaming\skype.ini
2013-05-06 11:13 - 2011-06-23 20:14 - 00000000 ____D C:\Users\ZS022\AppData\Roaming\uTorrent
2013-05-06 11:11 - 2012-12-11 10:20 - 00000946 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-05-05 21:23 - 2011-09-21 14:51 - 00000000 ____D C:\Users\ZS022\Desktop\Škola
2013-05-04 14:51 - 2013-05-04 14:56 - 00628743 ____A C:\Users\ZS022\Desktop\adwcleaner.exe
2013-05-04 13:38 - 2010-11-08 13:56 - 01923397 ____A C:\Windows\WindowsUpdate.log
2013-05-04 13:35 - 2009-07-14 05:45 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-05-04 13:35 - 2009-07-14 05:45 - 00016304 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-05-04 01:17 - 2012-12-11 10:20 - 00000950 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-05-04 01:10 - 2013-01-13 01:10 - 00000000 ____D C:\Users\ZS022\AppData\Roaming\Skype
2013-05-04 00:56 - 2013-03-15 08:41 - 00000914 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-05-03 23:58 - 2009-07-14 16:18 - 00635466 ____A C:\Windows\System32\perfh005.dat
2013-05-03 23:58 - 2009-07-14 16:18 - 00124208 ____A C:\Windows\System32\perfc005.dat
2013-05-03 23:58 - 2009-07-14 06:13 - 01482600 ____A C:\Windows\System32\PerfStringBackup.INI
2013-05-03 18:31 - 2013-05-03 18:24 - 248774454 ____A C:\Users\ZS022\Downloads\Greys.Anatomy.S09E22.HDTV.x264-LOL.mp4
2013-05-03 03:42 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports
2013-05-02 01:06 - 2011-04-17 10:49 - 00278800 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe
2013-04-30 11:49 - 2013-04-30 11:46 - 173500023 ____A C:\Users\ZS022\Downloads\How.I.Met.Your.Mother.S08E22.HDTV.x264-LOL.mp4
2013-04-29 21:11 - 2013-04-29 21:11 - 00078313 ____A C:\Users\ZS022\Downloads\model rustu prezentace.pptx
2013-04-29 18:22 - 2013-04-29 18:16 - 214040111 ____A C:\Users\ZS022\Downloads\Greys.Anatomy.S09E21.HDTV.x264-LOL.mp4
2013-04-27 13:28 - 2013-04-27 13:28 - 00278224 ____A C:\Windows\Minidump\042713-21216-01.dmp
2013-04-27 13:28 - 2013-02-12 09:09 - 00000000 ____D C:\Windows\Minidump
2013-04-25 20:15 - 2013-04-25 20:02 - 734777344 ____A C:\Users\ZS022\Downloads\The.Prestige.2006.DvDrip.Eng-aXXo.(
www.USABIT.com).avi
2013-04-25 07:31 - 2013-04-25 07:31 - 03891540 ____A C:\Users\ZS022\Downloads\Nippert_Karel-in_out_podk (1).rar
2013-04-24 22:49 - 2013-04-24 22:49 - 03891540 ____A C:\Users\ZS022\Downloads\Nippert_Karel-in_out_podk.rar
2013-04-22 18:26 - 2013-03-12 14:47 - 00000000 ____D C:\Users\ZS022\Desktop\Stisk
2013-04-21 21:22 - 2013-03-04 16:55 - 00000000 ____D C:\Users\ZS022\Desktop\PLATFORMA
2013-04-20 18:06 - 2013-04-20 17:57 - 00000000 ____D C:\Users\ZS022\Downloads\Submarine 2011 DVDRip Xvid UnKnOwN
2013-04-19 20:24 - 2013-04-19 20:23 - 00000000 ____D C:\Users\ZS022\Downloads\Shame.2011.LIMITED.DVDRip.XviD-AMIABLE
2013-04-18 23:05 - 2013-04-18 22:32 - 582048542 ____A C:\Users\ZS022\Downloads\Duna-audiokniha---cte-Igor-Smrzik-1993-(Herbert-Frank-audiobook)-CD1.zip
2013-04-18 20:33 - 2013-04-18 20:01 - 00000000 ____D C:\Users\ZS022\Downloads\Silver Linings Playbook (2012) [1080p]
2013-04-18 20:09 - 2013-04-18 20:09 - 00000000 ____D C:\Users\ZS022\Downloads\SILVER LININGS DVDRIP EDAW2013
2013-04-18 20:09 - 2013-04-18 20:07 - 00000000 ____D C:\Users\ZS022\Downloads\The.Mist[2007]DvDrip[Eng]-aXXo
2013-04-18 11:30 - 2012-02-02 10:25 - 00000000 ____D C:\Users\ZS022\Desktop\fotky
2013-04-17 20:35 - 2013-04-17 19:44 - 00000000 ____D C:\Users\ZS022\Downloads\V for Vendetta (2006) [1080p]
2013-04-16 20:42 - 2013-04-16 20:42 - 00071847 ____A C:\Users\ZS022\Downloads\Donnie-Darko(0000178790).srt
2013-04-16 19:39 - 2013-04-16 19:38 - 00000000 ____D C:\Users\ZS022\Downloads\Donnie Darko DIRECTORS CUT (2001) [1080p]
2013-04-16 15:05 - 2013-03-14 14:10 - 00000000 ____D C:\Users\ZS022\Desktop\shake
2013-04-16 12:10 - 2013-04-16 12:02 - 178269063 ____A C:\Users\ZS022\Downloads\How.I.Met.Your.Mother.S08E21.HDTV.x264-LOL.mp4
2013-04-14 12:06 - 2013-04-14 12:06 - 00558738 ____A C:\Users\ZS022\Downloads\Bez názvu 2.psd
2013-04-13 14:44 - 2013-04-13 14:44 - 00109609 ____A C:\Users\ZS022\Downloads\levibrush.zip
2013-04-12 15:45 - 2013-04-24 08:50 - 01656680 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ntfs.sys
2013-04-11 09:32 - 2010-11-08 14:10 - 00070662 ____A C:\Windows\PFRO.log
2013-04-11 09:28 - 2013-04-11 09:29 - 00262560 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-04-11 09:28 - 2013-04-11 09:29 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-04-11 09:28 - 2013-04-11 09:29 - 00174496 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-04-11 09:28 - 2012-12-31 13:31 - 00095648 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-04-11 09:28 - 2012-08-21 14:31 - 00861088 ____A (Oracle Corporation) C:\Windows\SysWOW64\npdeployJava1.dll
2013-04-11 09:28 - 2010-09-13 14:54 - 00782240 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-04-11 09:24 - 2013-04-11 09:23 - 00896928 ____A (Oracle Corporation) C:\Users\ZS022\Downloads\chromeinstall-7u17.exe
2013-04-11 09:23 - 2011-04-18 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-04-10 22:49 - 2009-07-14 05:45 - 05061208 ____A C:\Windows\System32\FNTCACHE.DAT
2013-04-10 22:42 - 2011-09-14 14:02 - 72702784 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-04-10 22:40 - 2011-04-04 11:28 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-04-10 12:26 - 2013-04-10 12:26 - 03919253 ____A C:\Users\ZS022\Downloads\vecurek.rar
2013-04-10 08:40 - 2013-04-10 08:40 - 04553504 ____A C:\Users\ZS022\Downloads\Petru_Vaclav-Vaclav_Petru_in__out.rar
Other Malware:
===========
C:\Users\ZS022\AppData\Roaming\skype.dat
C:\Users\ZS022\AppData\Roaming\skype.ini
C:\ProgramData\0tbpw.bat
C:\ProgramData\0tbpw.pad
C:\ProgramData\0tbpw.reg
C:\ProgramData\ezsidmv.dat
==================== Known DLLs (Whitelisted) ================
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
==================== EXE ASSOCIATION =====================
HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK
==================== Restore Points =========================
Restore point made on: 2013-04-27 17:49:26
Restore point made on: 2013-05-01 08:14:01
==================== Memory info ===========================
Percentage of memory in use: 18%
Total physical RAM: 2930.67 MB
Available physical RAM: 2393.66 MB
Total Pagefile: 2928.82 MB
Available Pagefile: 2389.13 MB
Total Virtual: 8192 MB
Available Virtual: 8191.88 MB
==================== Drives ================================
Drive c: (WINDOWS) (Fixed) (Total:149.04 GB) (Free:15.92 GB) NTFS (Disk=0 Partition=2)
Drive d: (Data) (Fixed) (Total:148.65 GB) (Free:2.5 GB) NTFS (Disk=0 Partition=3)
Drive e: (SYSTEM) (Fixed) (Total:0.39 GB) (Free:0.18 GB) NTFS (Disk=0 Partition=1) ==>[System with boot components (obtained from reading drive)]
Drive f: (InstallWin7*) (CDROM) (Total:3.69 GB) (Free:0 GB) CDFS
Drive h: () (Removable) (Total:0.92 GB) (Free:0.92 GB) FAT (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
==================== MBR & Partition Table ==================
====================================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: DB5AF07F)
Partition 1: (Active) - (Size=400 MB) - (Type=27)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
====================================================================
Disk: 2 (Size: 946 MB) (Disk ID: 20796B73)
Partition 1: (Not Active) - (Size=834 GB) - (Type=A0)
Partition 2: (Not Active) - (Size=932 GB) - (Type=64)
Partition 3: (Not Active) - (Size=-820995801088) - (Type=6A)
Partition 4: (Not Active) - (Size=-336796844032) - (Type=75)
Last Boot: 2013-04-24 07:57
==================== End Of Log ============================