Prosím o kontrolu logu vir PČR
Napsal: 02 srp 2013 19:12
Ahoj kámoš zrovna dostal do noťasu nejnovější verzi tohoto viru, který zablokovává nouzový režim log jsem udělal podle návodu co tu je, prosím tedy o kontrolu a následný postup jak se ho zbavit bez přeinstalování systému. Díky
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013
Ran by JB (administrator) on 02-08-2013 16:23:27
Running from J:\
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-28] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-18] (IDT, Inc.)
HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [611896 2010-01-20] ()
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
HKLM-x32\...\Winlogon: [Shell] explorer.exe shell.exe [x ] () <=== ATTENTION
HKCU\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-06-16] (Hewlett-Packard Company)
HKCU\...\Run: [Google Update] - C:\Users\JB\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-08-29] (Google Inc.)
HKCU\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [1022352 2012-09-02] (BitTorrent, Inc.)
HKCU\...\Run: [StudentDOG] - C:\Program Files (x86)\Programs\Student DOG\StudentDOG.exe [2102272 2011-01-02] ()
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKCU\...\Run: [BlazeServoTool] - "C:\Program Files (x86)\BlazeVideo\BlazeVideo HDTV Player 6.6 Professional\MediaDetector.exe" [x]
HKCU\...\Run: [Facebook Update] - C:\Users\JB\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-13] (Facebook Inc.)
HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [774144 2009-12-08] (Sony Ericsson Mobile Communications AB)
HKCU\...\Run: [EPSON SX125 Series] - C:\Windows\TEMP\E_S1F73.tmp [126 2012-05-31] ()
HKCU\...\Run: [SanDiskSecureAccess_Manager.exe] - C:\Users\JB\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-12-28] (Gemalto N.V.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1641896 2013-06-07] (Valve Corporation)
HKCU\...\Run: [Tiiait] - C:\Users\JB\AppData\Roaming\Tiiait.exe [x]
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\JB\AppData\Roaming\cache.dat [90624 2011-11-17] () <==== ATTENTION
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
MountPoints2: {2835cad8-d754-11e1-b8e5-70f39567e6b4} - I:\autorun.exe
MountPoints2: {37fffdac-cf20-11e1-a652-70f39567e6b4} - G:\CDCheck.exe
MountPoints2: {37fffdb4-cf20-11e1-a652-70f39567e6b4} - H:\CDCheck.exe
MountPoints2: {61b60b3c-9e09-11e1-9d5e-70f39539fccc} - G:\Startme.exe
MountPoints2: {6e7a5b16-f35c-11e0-a1b6-99211a016dba} - F:\setup\rsrc\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-06-02] (EasyBits Software AS)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [ConduitHelper] - C:\Users\Public\Conduit\ConduitHelper\ConduitHelper.exe [274216 2011-08-31] (Conduit Ltd.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [avast5] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [2837864 2010-06-28] (AVAST Software)
HKLM-x32\...\Run: [Guard.Mail.ru.gui] - C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-11-21] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://qip.ru
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
URLSearchHook: (No Name) - {95289393-33EA-4F8D-B952-483415B9C955} - No File
URLSearchHook: (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {19882090-72DA-4D5F-8AC6-7E7BE5FF1C09} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL =
SearchScopes: HKLM-x32 - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKCU - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM-x32 - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52920 2010-08-17] (EasyBits Software Corp.)
ShellExecuteHooks-x32: - UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File [ ]
ShellExecuteHooks-x32: - {DAE0285D-0788-4E87-985E-01DF2EDE4ACD} - C:\Windows\SysWow64\Wshxt.dll [53248 2012-07-16] ()
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Windows Live\\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\JB\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Google Update) - C:\Users\JB\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Collorfull Parking lot) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\hihiejogcgadaaodnnebjbmflfopemlg\1_0
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0
CHR Extension: (Gmail) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\JB\AppData\Local\Temp\crxE2D1.tmp
CHR StartMenuInternet: Google Chrome - C:\Users\JB\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
S2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S3 avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S3 avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S2 Guard.Mail.ru; C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-11-21] ()
S2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] ()
S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [40999448 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2012-12-05] ()
S2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [107832 2012-12-05] ()
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [369688 2008-07-10] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [20048 2010-06-28] (ALWIL Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [61008 2010-06-28] (ALWIL Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [28752 2010-06-28] (ALWIL Software)
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [432720 2010-06-28] (ALWIL Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [121936 2010-06-28] (ALWIL Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [51280 2010-06-28] (ALWIL Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-10-11] (DT Soft Ltd)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [164864 2012-07-10] (ITE )
S3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [19496 2009-03-25] (MCCI Corporation)
S3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [153128 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [34856 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [42896 2010-06-08] (Oracle Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-02 16:23 - 2013-08-02 16:23 - 00000000 ____D C:\FRST
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Downloads\aswclear.exe
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Desktop\aswclear.exe
2013-07-31 16:44 - 2013-07-31 18:01 - 00000004 _____ C:\Users\JB\AppData\Roaming\cache.ini
2013-07-31 16:39 - 2013-07-31 16:31 - 00090624 _____ C:\Users\JB\Desktop\video_hd.exe
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd.zip
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd (1).zip
2013-07-31 13:14 - 2013-07-31 13:14 - 00000000 _____ C:\Users\JB\Desktop\stažený soubor.htm
2013-07-29 19:23 - 2013-07-29 19:26 - 26419203 _____ C:\Users\JB\Desktop\Hudební dno.wmv
2013-07-29 09:49 - 2013-07-29 09:49 - 00001976 _____ C:\Users\JB\Downloads\Provozní na ubytovně Ostrava www.avizo.cz.url
2013-07-29 09:48 - 2013-07-29 09:48 - 00014093 _____ C:\Users\JB\Downloads\visa[1].html
2013-07-28 18:20 - 2013-07-28 19:39 - 733585196 _____ C:\Users\JB\Desktop\Milionář-z-chatrče-CZ.avi
2013-07-28 17:47 - 2013-07-28 17:47 - 00000000 ____D C:\Users\JB\Desktop\F
2013-07-28 10:27 - 2013-07-28 10:27 - 00000031 _____ C:\Users\JB\Downloads\ostrava.mp3.m3u
2013-07-25 21:06 - 2013-07-25 21:06 - 00000000 ____D C:\Users\JB\Desktop\Big Bang theory CZ
2013-07-25 21:04 - 2013-07-25 21:04 - 00064193 _____ C:\Users\JB\Desktop\[CzT]Teorie_velkeho_tresku_Big_Bang_theory_1_5_serie_CZ_TVRip_.torrent
2013-07-25 19:57 - 2013-07-25 20:38 - 736137216 _____ C:\Users\JB\Desktop\Percy-Jackson-Zlodej-blesku-(Percy-Jackson-&-the-Olympians-The-Lightning-Thief).avi
2013-07-25 06:17 - 2013-07-25 06:17 - 00000000 ____D C:\Windows\system32\MRT
2013-07-14 19:25 - 2013-07-16 19:24 - 00000000 ____D C:\Users\JB\Documents\Prototype
2013-07-14 19:23 - 2013-07-14 19:23 - 00001612 _____ C:\Users\JB\Desktop\prototype.lnk
2013-07-14 19:11 - 2013-07-14 19:19 - 00000000 ____D C:\Root
2013-07-14 18:32 - 2009-06-09 21:06 - 3674800128 _____ C:\Users\JB\Desktop\rzr-prot.iso
2013-07-13 19:31 - 2013-07-13 19:31 - 00002368 _____ C:\Users\JB\Downloads\Pomocný dělník ve výrobě - Volné pracovní místo OSTRAVA.url
2013-07-13 08:57 - 2009-09-16 22:29 - 29161790 _____ (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) C:\Users\JB\Desktop\nemcina-demo.exe
2013-07-13 08:56 - 2013-07-13 08:56 - 29108498 _____ C:\Users\JB\Downloads\nedemo.zip
2013-07-11 10:53 - 2013-07-11 10:53 - 00071438 _____ C:\Users\JB\Downloads\[CzT]Harry-Potter-Komplet-CZ-by-James.torrent
2013-07-11 09:48 - 2013-07-11 10:40 - 935385786 _____ C:\Users\JB\Desktop\Zálesák---Forest-Warrior---Chuck-Norris--Rodinný-Dobrodružný-Komedie-Akční-USA,-1996,-budul-93-min-cz.avi
2013-07-11 09:17 - 2013-07-12 10:06 - 00000000 ____D C:\Users\JB\Downloads\constantine
2013-07-11 09:16 - 2013-07-11 09:16 - 00019480 _____ C:\Users\JB\Downloads\[CzT]Constantine_Constantine_2005_.torrent
2013-07-11 09:15 - 2013-07-11 09:15 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ (1).torrent
2013-07-10 18:29 - 2013-07-10 18:29 - 00013002 _____ C:\Users\JB\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2013-07-09 17:21 - 2013-07-09 17:21 - 00001117 _____ C:\Users\JB\Downloads\Soustružník Ostrava-Kunčice Dobrá práce.cz (3).url
2013-07-08 20:56 - 2013-07-08 20:59 - 00000000 ____D C:\Users\JB\Desktop\Constantine
2013-07-08 20:50 - 2013-07-08 20:50 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ.torrent
2013-07-08 20:03 - 2013-07-08 19:27 - 03090483 _____ C:\Users\JB\Desktop\VID_20130708_192635.3gp
2013-07-08 13:35 - 2013-07-08 13:35 - 00001418 _____ C:\Users\JB\Downloads\vazač-ka, FRYMEL TRADE s.r.o. - Ostrava.url
2013-07-08 13:32 - 2013-07-08 13:33 - 00002239 _____ C:\Users\JB\Downloads\strážný-á - recepční, AVES Servisní a.s. - Ostrava.url
2013-07-08 07:30 - 2013-07-08 07:30 - 00001813 _____ C:\Users\JB\Desktop\993897_10201776920172561_133108716_n.jpg – zástupce.lnk
2013-07-06 17:50 - 2013-07-06 17:50 - 00000000 ____D C:\Users\JB\Desktop\Fretka
2013-07-04 12:32 - 2013-07-16 09:22 - 00003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJB
2013-07-04 12:32 - 2013-07-16 09:22 - 00000320 _____ C:\Windows\Tasks\HPCeeScheduleForJB.job
==================== One Month Modified Files and Folders =======
2013-08-02 16:18 - 2010-08-18 03:02 - 05977784 _____ C:\Windows\system32\perfh005.dat
2013-08-02 16:18 - 2010-08-18 03:02 - 01985862 _____ C:\Windows\system32\perfc005.dat
2013-08-02 16:18 - 2009-07-14 07:13 - 00005596 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-01 07:22 - 2011-10-12 04:00 - 00000000 ____D C:\ProgramData\Recovery
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Downloads\aswclear.exe
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Desktop\aswclear.exe
2013-07-31 18:25 - 2010-08-19 01:44 - 02042314 _____ C:\Windows\WindowsUpdate.log
2013-07-31 18:03 - 2011-08-29 12:33 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA.job
2013-07-31 18:01 - 2013-07-31 16:44 - 00000004 _____ C:\Users\JB\AppData\Roaming\cache.ini
2013-07-31 17:43 - 2011-09-05 14:38 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1003UA.job
2013-07-31 17:40 - 2011-08-30 09:35 - 00000000 ____D C:\Users\JB\AppData\Roaming\Skype
2013-07-31 17:37 - 2013-03-03 17:51 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 16:45 - 2012-03-14 12:58 - 00000970 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA.job
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd.zip
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd (1).zip
2013-07-31 16:31 - 2013-07-31 16:39 - 00090624 _____ C:\Users\JB\Desktop\video_hd.exe
2013-07-31 14:43 - 2011-09-05 14:38 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1003Core.job
2013-07-31 13:14 - 2013-07-31 13:14 - 00000000 _____ C:\Users\JB\Desktop\stažený soubor.htm
2013-07-30 22:03 - 2011-08-29 12:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core.job
2013-07-30 19:45 - 2012-03-14 12:58 - 00000948 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core.job
2013-07-30 09:22 - 2011-11-08 10:55 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-07-30 09:22 - 2011-09-13 21:14 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-07-30 01:07 - 2012-07-16 13:18 - 00003974 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{32C8AE03-4433-4784-9F4A-A70B78AA895A}
2013-07-29 19:26 - 2013-07-29 19:23 - 26419203 _____ C:\Users\JB\Desktop\Hudební dno.wmv
2013-07-29 09:49 - 2013-07-29 09:49 - 00001976 _____ C:\Users\JB\Downloads\Provozní na ubytovně Ostrava www.avizo.cz.url
2013-07-29 09:48 - 2013-07-29 09:48 - 00014093 _____ C:\Users\JB\Downloads\visa[1].html
2013-07-29 07:55 - 2011-09-17 18:20 - 00000000 ____D C:\Users\JB\AppData\Roaming\uTorrent
2013-07-28 22:25 - 2011-09-26 07:59 - 00000000 ___RD C:\Users\JB\Desktop\My Shared Folder
2013-07-28 19:39 - 2013-07-28 18:20 - 733585196 _____ C:\Users\JB\Desktop\Milionář-z-chatrče-CZ.avi
2013-07-28 17:47 - 2013-07-28 17:47 - 00000000 ____D C:\Users\JB\Desktop\F
2013-07-28 17:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-28 10:27 - 2013-07-28 10:27 - 00000031 _____ C:\Users\JB\Downloads\ostrava.mp3.m3u
2013-07-25 21:06 - 2013-07-25 21:06 - 00000000 ____D C:\Users\JB\Desktop\Big Bang theory CZ
2013-07-25 21:04 - 2013-07-25 21:04 - 00064193 _____ C:\Users\JB\Desktop\[CzT]Teorie_velkeho_tresku_Big_Bang_theory_1_5_serie_CZ_TVRip_.torrent
2013-07-25 20:38 - 2013-07-25 19:57 - 736137216 _____ C:\Users\JB\Desktop\Percy-Jackson-Zlodej-blesku-(Percy-Jackson-&-the-Olympians-The-Lightning-Thief).avi
2013-07-25 06:21 - 2013-07-25 06:17 - 00000000 ____D C:\Windows\system32\MRT
2013-07-18 18:28 - 2011-09-26 07:59 - 00000000 ____D C:\Users\JB\AppData\Local\Ares
2013-07-18 14:36 - 2009-07-14 06:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-18 14:36 - 2009-07-14 06:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-16 19:24 - 2013-07-14 19:25 - 00000000 ____D C:\Users\JB\Documents\Prototype
2013-07-16 09:22 - 2013-07-04 12:32 - 00003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJB
2013-07-16 09:22 - 2013-07-04 12:32 - 00000320 _____ C:\Windows\Tasks\HPCeeScheduleForJB.job
2013-07-16 09:22 - 2012-07-16 12:41 - 00003226 _____ C:\Windows\System32\Tasks\HPCeeScheduleForFBI_PROPERTY$
2013-07-16 09:22 - 2012-07-16 12:41 - 00000350 _____ C:\Windows\Tasks\HPCeeScheduleForFBI_PROPERTY$.job
2013-07-14 19:23 - 2013-07-14 19:23 - 00001612 _____ C:\Users\JB\Desktop\prototype.lnk
2013-07-14 19:20 - 2011-08-29 12:02 - 00429443 _____ C:\Windows\DirectX.log
2013-07-14 19:19 - 2013-07-14 19:11 - 00000000 ____D C:\Root
2013-07-14 19:19 - 2010-08-17 17:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-14 19:11 - 2013-03-03 18:33 - 00000000 ____D C:\Program Files (x86)\Activision
2013-07-13 19:31 - 2013-07-13 19:31 - 00002368 _____ C:\Users\JB\Downloads\Pomocný dělník ve výrobě - Volné pracovní místo OSTRAVA.url
2013-07-13 08:56 - 2013-07-13 08:56 - 29108498 _____ C:\Users\JB\Downloads\nedemo.zip
2013-07-12 21:58 - 2011-08-29 12:33 - 00003914 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA
2013-07-12 21:58 - 2011-08-29 12:33 - 00003518 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core
2013-07-12 14:04 - 2013-06-11 11:07 - 00000000 ____D C:\Program Files (x86)\Steam
2013-07-12 14:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-12 14:02 - 2009-07-14 06:51 - 00184316 _____ C:\Windows\setupact.log
2013-07-12 10:06 - 2013-07-11 09:17 - 00000000 ____D C:\Users\JB\Downloads\constantine
2013-07-11 12:33 - 2012-05-13 08:06 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 12:33 - 2012-05-13 08:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 10:53 - 2013-07-11 10:53 - 00071438 _____ C:\Users\JB\Downloads\[CzT]Harry-Potter-Komplet-CZ-by-James.torrent
2013-07-11 10:40 - 2013-07-11 09:48 - 935385786 _____ C:\Users\JB\Desktop\Zálesák---Forest-Warrior---Chuck-Norris--Rodinný-Dobrodružný-Komedie-Akční-USA,-1996,-budul-93-min-cz.avi
2013-07-11 09:16 - 2013-07-11 09:16 - 00019480 _____ C:\Users\JB\Downloads\[CzT]Constantine_Constantine_2005_.torrent
2013-07-11 09:15 - 2013-07-11 09:15 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ (1).torrent
2013-07-11 07:40 - 2011-08-29 17:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-10 18:37 - 2012-12-05 22:09 - 00000000 ____D C:\Users\JB\Desktop\Plocha
2013-07-10 18:29 - 2013-07-10 18:29 - 00013002 _____ C:\Users\JB\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2013-07-09 17:21 - 2013-07-09 17:21 - 00001117 _____ C:\Users\JB\Downloads\Soustružník Ostrava-Kunčice Dobrá práce.cz (3).url
2013-07-08 20:59 - 2013-07-08 20:56 - 00000000 ____D C:\Users\JB\Desktop\Constantine
2013-07-08 20:50 - 2013-07-08 20:50 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ.torrent
2013-07-08 19:27 - 2013-07-08 20:03 - 03090483 _____ C:\Users\JB\Desktop\VID_20130708_192635.3gp
2013-07-08 13:35 - 2013-07-08 13:35 - 00001418 _____ C:\Users\JB\Downloads\vazač-ka, FRYMEL TRADE s.r.o. - Ostrava.url
2013-07-08 13:33 - 2013-07-08 13:32 - 00002239 _____ C:\Users\JB\Downloads\strážný-á - recepční, AVES Servisní a.s. - Ostrava.url
2013-07-08 07:30 - 2013-07-08 07:30 - 00001813 _____ C:\Users\JB\Desktop\993897_10201776920172561_133108716_n.jpg – zástupce.lnk
2013-07-06 17:50 - 2013-07-06 17:50 - 00000000 ____D C:\Users\JB\Desktop\Fretka
Files to move or delete:
====================
C:\Users\JB\AppData\Roaming\cache.dat
C:\Users\JB\AppData\Roaming\cache.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
safeboot: ==> The system is configured to boot to Safe Mode <===== ATTENTION!
LastRegBack: 2013-07-03 11:45
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013
Ran by JB (administrator) on 02-08-2013 16:23:27
Running from J:\
Windows 7 Home Premium (X64) OS Language: Czech
Internet Explorer Version 8
Boot Mode: Safe Mode (minimal)
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\cmd.exe
(DigitalPersona, Inc.) C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-28] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-06-18] (IDT, Inc.)
HKLM\...\Run: [SmartMenu] - C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [611896 2010-01-20] ()
HKLM\...\Run: [HPWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe [363064 2010-06-18] (Hewlett-Packard Company)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe,
HKLM-x32\...\Winlogon: [Shell] explorer.exe shell.exe [x ] () <=== ATTENTION
HKCU\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\Dock\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKCU\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe [2736128 2010-06-16] (Hewlett-Packard Company)
HKCU\...\Run: [Google Update] - C:\Users\JB\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-08-29] (Google Inc.)
HKCU\...\Run: [uTorrent] - C:\Program Files (x86)\uTorrent\uTorrent.exe [1022352 2012-09-02] (BitTorrent, Inc.)
HKCU\...\Run: [StudentDOG] - C:\Program Files (x86)\Programs\Student DOG\StudentDOG.exe [2102272 2011-01-02] ()
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [1305408 2011-01-20] (DT Soft Ltd)
HKCU\...\Run: [BlazeServoTool] - "C:\Program Files (x86)\BlazeVideo\BlazeVideo HDTV Player 6.6 Professional\MediaDetector.exe" [x]
HKCU\...\Run: [Facebook Update] - C:\Users\JB\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-07-13] (Facebook Inc.)
HKCU\...\Run: [Sony Ericsson PC Companion] - C:\Program Files (x86)\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe [774144 2009-12-08] (Sony Ericsson Mobile Communications AB)
HKCU\...\Run: [EPSON SX125 Series] - C:\Windows\TEMP\E_S1F73.tmp [126 2012-05-31] ()
HKCU\...\Run: [SanDiskSecureAccess_Manager.exe] - C:\Users\JB\AppData\Roaming\SanDisk\SanDiskSecureAccess_Manager.exe [30705792 2012-12-28] (Gemalto N.V.)
HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18678376 2013-04-19] (Skype Technologies S.A.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\steam.exe [1641896 2013-06-07] (Valve Corporation)
HKCU\...\Run: [Tiiait] - C:\Users\JB\AppData\Roaming\Tiiait.exe [x]
HKCU\...\Winlogon: [Shell] explorer.exe,C:\Users\JB\AppData\Roaming\cache.dat [90624 2011-11-17] () <==== ATTENTION
HKCU\...\Policies\system: [DisableLockWorkstation] 0
HKCU\...\Policies\system: [DisableChangePassword] 0
MountPoints2: {2835cad8-d754-11e1-b8e5-70f39567e6b4} - I:\autorun.exe
MountPoints2: {37fffdac-cf20-11e1-a652-70f39567e6b4} - G:\CDCheck.exe
MountPoints2: {37fffdb4-cf20-11e1-a652-70f39567e6b4} - H:\CDCheck.exe
MountPoints2: {61b60b3c-9e09-11e1-9d5e-70f39539fccc} - G:\Startme.exe
MountPoints2: {6e7a5b16-f35c-11e0-a1b6-99211a016dba} - F:\setup\rsrc\Autorun.exe
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [602168 2010-06-29] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2010-06-02] (EasyBits Software AS)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2010-03-12] (Hewlett-Packard)
HKLM-x32\...\Run: [] - [x]
HKLM-x32\...\Run: [ConduitHelper] - C:\Users\Public\Conduit\ConduitHelper\ConduitHelper.exe [274216 2011-08-31] (Conduit Ltd.)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [843712 2012-01-02] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HTC Sync Loader] - C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe [249856 2010-09-08] ()
HKLM-x32\...\Run: [avast5] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [2837864 2010-06-28] (AVAST Software)
HKLM-x32\...\Run: [Guard.Mail.ru.gui] - C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-11-21] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKU\Default\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
HKU\Default User\...\Run: [HPAdvisorDock] - C:\Program Files (x86)\Hewlett-Packard\HP Advisor\DOCK\HPAdvisorDock.exe [1712184 2010-02-09] ()
Lsa: [Notification Packages] DPPassFilter scecli
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = http://search.icq.com/search/results.ph ... &ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://qip.ru
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com
URLSearchHook: (No Name) - {95289393-33EA-4F8D-B952-483415B9C955} - No File
URLSearchHook: (No Name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {19882090-72DA-4D5F-8AC6-7E7BE5FF1C09} URL = http://www.bing.com/search?q={searchTer ... -SearchBox
SearchScopes: HKLM - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKLM-x32 - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL =
SearchScopes: HKLM-x32 - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
SearchScopes: HKCU - DefaultScope {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={ ... rer:source?}
SearchScopes: HKCU - {4140AE61-F20F-4396-B7A1-3C1CDD0DE234} URL = http://cs.wikipedia.org/wiki/Special:Se ... earchTerms}
SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = http://search.icq.com/search/results.ph ... &ch_id=osd
SearchScopes: HKCU - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} URL = http://search.qip.ru/search?query={searchTerms}&from=IE
SearchScopes: HKCU - {AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} URL = http://www.daemon-search.com/search?q={searchTerms}
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = http://search.conduit.com/ResultsExt.as ... =CT2786678
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: Bing Bar Helper - {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - C:\Program Files (x86)\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Toolbar: HKLM-x32 - uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files (x86)\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.2.233.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKCU - No Name - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
Toolbar: HKCU - DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL [52920 2010-08-17] (EasyBits Software Corp.)
ShellExecuteHooks-x32: - UPB:{B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No File [ ]
ShellExecuteHooks-x32: - {DAE0285D-0788-4E87-985E-01DF2EDE4ACD} - C:\Windows\SysWow64\Wshxt.dll [53248 2012-07-16] ()
Chrome:
=======
CHR HomePage: hxxp://www.seznam.cz/
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\JB\AppData\Local\Google\Chrome\Application\28.0.1500.72\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.200.2) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U20) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll No File
CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Windows Live\\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\JB\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Google Update) - C:\Users\JB\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (Collorfull Parking lot) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\hihiejogcgadaaodnnebjbmflfopemlg\1_0
CHR Extension: (Windows Media Player Extension for HTML5) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\hokdglbhghcebcopdbanieangmcamaak\1.0_0
CHR Extension: (Gmail) - C:\Users\JB\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1
CHR HKLM-x32\...\Chrome\Extension: [bejbohlohkkgompgecdcbbglkpjfjgdj] - C:\Users\JB\AppData\Local\Temp\crxE2D1.tmp
CHR StartMenuInternet: Google Chrome - C:\Users\JB\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
S2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S3 avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S3 avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [40384 2010-06-28] (AVAST Software)
S2 Guard.Mail.ru; C:\Program Files (x86)\Guard-ICQ\GuardICQ.exe [1564368 2012-11-21] ()
S2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [27192 2010-06-29] ()
S2 MSSQL$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [40999448 2008-07-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe [4737024 2008-07-29] (Microsoft Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [79872 2010-09-07] ()
S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [66872 2012-12-05] ()
S2 PnkBstrB; C:\Windows\SysWow64\PnkBstrB.exe [107832 2012-12-05] ()
S4 SQLAgent$SQLEXPRESS; c:\Program Files (x86)\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [369688 2008-07-10] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [20048 2010-06-28] (ALWIL Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [61008 2010-06-28] (ALWIL Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [28752 2010-06-28] (ALWIL Software)
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [432720 2010-06-28] (ALWIL Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [121936 2010-06-28] (ALWIL Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [51280 2010-06-28] (ALWIL Software)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-10-11] (DT Soft Ltd)
S3 IT9135BDA; C:\Windows\System32\Drivers\IT9135BDA.sys [164864 2012-07-10] (ITE )
S3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [113704 2009-03-25] (MCCI Corporation)
S3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [19496 2009-03-25] (MCCI Corporation)
S3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [153128 2009-03-25] (MCCI Corporation)
S3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [133160 2009-03-25] (MCCI Corporation)
S3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [34856 2009-03-25] (MCCI Corporation)
S3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [128552 2009-03-25] (MCCI Corporation)
S3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [146472 2009-03-25] (MCCI Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [42896 2010-06-08] (Oracle Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-02 16:23 - 2013-08-02 16:23 - 00000000 ____D C:\FRST
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Downloads\aswclear.exe
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Desktop\aswclear.exe
2013-07-31 16:44 - 2013-07-31 18:01 - 00000004 _____ C:\Users\JB\AppData\Roaming\cache.ini
2013-07-31 16:39 - 2013-07-31 16:31 - 00090624 _____ C:\Users\JB\Desktop\video_hd.exe
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd.zip
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd (1).zip
2013-07-31 13:14 - 2013-07-31 13:14 - 00000000 _____ C:\Users\JB\Desktop\stažený soubor.htm
2013-07-29 19:23 - 2013-07-29 19:26 - 26419203 _____ C:\Users\JB\Desktop\Hudební dno.wmv
2013-07-29 09:49 - 2013-07-29 09:49 - 00001976 _____ C:\Users\JB\Downloads\Provozní na ubytovně Ostrava www.avizo.cz.url
2013-07-29 09:48 - 2013-07-29 09:48 - 00014093 _____ C:\Users\JB\Downloads\visa[1].html
2013-07-28 18:20 - 2013-07-28 19:39 - 733585196 _____ C:\Users\JB\Desktop\Milionář-z-chatrče-CZ.avi
2013-07-28 17:47 - 2013-07-28 17:47 - 00000000 ____D C:\Users\JB\Desktop\F
2013-07-28 10:27 - 2013-07-28 10:27 - 00000031 _____ C:\Users\JB\Downloads\ostrava.mp3.m3u
2013-07-25 21:06 - 2013-07-25 21:06 - 00000000 ____D C:\Users\JB\Desktop\Big Bang theory CZ
2013-07-25 21:04 - 2013-07-25 21:04 - 00064193 _____ C:\Users\JB\Desktop\[CzT]Teorie_velkeho_tresku_Big_Bang_theory_1_5_serie_CZ_TVRip_.torrent
2013-07-25 19:57 - 2013-07-25 20:38 - 736137216 _____ C:\Users\JB\Desktop\Percy-Jackson-Zlodej-blesku-(Percy-Jackson-&-the-Olympians-The-Lightning-Thief).avi
2013-07-25 06:17 - 2013-07-25 06:17 - 00000000 ____D C:\Windows\system32\MRT
2013-07-14 19:25 - 2013-07-16 19:24 - 00000000 ____D C:\Users\JB\Documents\Prototype
2013-07-14 19:23 - 2013-07-14 19:23 - 00001612 _____ C:\Users\JB\Desktop\prototype.lnk
2013-07-14 19:11 - 2013-07-14 19:19 - 00000000 ____D C:\Root
2013-07-14 18:32 - 2009-06-09 21:06 - 3674800128 _____ C:\Users\JB\Desktop\rzr-prot.iso
2013-07-13 19:31 - 2013-07-13 19:31 - 00002368 _____ C:\Users\JB\Downloads\Pomocný dělník ve výrobě - Volné pracovní místo OSTRAVA.url
2013-07-13 08:57 - 2009-09-16 22:29 - 29161790 _____ (Xceed Software Inc. 1-450-442-2626 info@xceedsoft.com www.xceedsoft.com) C:\Users\JB\Desktop\nemcina-demo.exe
2013-07-13 08:56 - 2013-07-13 08:56 - 29108498 _____ C:\Users\JB\Downloads\nedemo.zip
2013-07-11 10:53 - 2013-07-11 10:53 - 00071438 _____ C:\Users\JB\Downloads\[CzT]Harry-Potter-Komplet-CZ-by-James.torrent
2013-07-11 09:48 - 2013-07-11 10:40 - 935385786 _____ C:\Users\JB\Desktop\Zálesák---Forest-Warrior---Chuck-Norris--Rodinný-Dobrodružný-Komedie-Akční-USA,-1996,-budul-93-min-cz.avi
2013-07-11 09:17 - 2013-07-12 10:06 - 00000000 ____D C:\Users\JB\Downloads\constantine
2013-07-11 09:16 - 2013-07-11 09:16 - 00019480 _____ C:\Users\JB\Downloads\[CzT]Constantine_Constantine_2005_.torrent
2013-07-11 09:15 - 2013-07-11 09:15 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ (1).torrent
2013-07-10 18:29 - 2013-07-10 18:29 - 00013002 _____ C:\Users\JB\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2013-07-09 17:21 - 2013-07-09 17:21 - 00001117 _____ C:\Users\JB\Downloads\Soustružník Ostrava-Kunčice Dobrá práce.cz (3).url
2013-07-08 20:56 - 2013-07-08 20:59 - 00000000 ____D C:\Users\JB\Desktop\Constantine
2013-07-08 20:50 - 2013-07-08 20:50 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ.torrent
2013-07-08 20:03 - 2013-07-08 19:27 - 03090483 _____ C:\Users\JB\Desktop\VID_20130708_192635.3gp
2013-07-08 13:35 - 2013-07-08 13:35 - 00001418 _____ C:\Users\JB\Downloads\vazač-ka, FRYMEL TRADE s.r.o. - Ostrava.url
2013-07-08 13:32 - 2013-07-08 13:33 - 00002239 _____ C:\Users\JB\Downloads\strážný-á - recepční, AVES Servisní a.s. - Ostrava.url
2013-07-08 07:30 - 2013-07-08 07:30 - 00001813 _____ C:\Users\JB\Desktop\993897_10201776920172561_133108716_n.jpg – zástupce.lnk
2013-07-06 17:50 - 2013-07-06 17:50 - 00000000 ____D C:\Users\JB\Desktop\Fretka
2013-07-04 12:32 - 2013-07-16 09:22 - 00003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJB
2013-07-04 12:32 - 2013-07-16 09:22 - 00000320 _____ C:\Windows\Tasks\HPCeeScheduleForJB.job
==================== One Month Modified Files and Folders =======
2013-08-02 16:18 - 2010-08-18 03:02 - 05977784 _____ C:\Windows\system32\perfh005.dat
2013-08-02 16:18 - 2010-08-18 03:02 - 01985862 _____ C:\Windows\system32\perfc005.dat
2013-08-02 16:18 - 2009-07-14 07:13 - 00005596 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-01 07:22 - 2011-10-12 04:00 - 00000000 ____D C:\ProgramData\Recovery
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Downloads\aswclear.exe
2013-07-31 18:25 - 2013-07-31 18:25 - 00377920 _____ (AVAST Software) C:\Users\JB\Desktop\aswclear.exe
2013-07-31 18:25 - 2010-08-19 01:44 - 02042314 _____ C:\Windows\WindowsUpdate.log
2013-07-31 18:03 - 2011-08-29 12:33 - 00000950 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA.job
2013-07-31 18:01 - 2013-07-31 16:44 - 00000004 _____ C:\Users\JB\AppData\Roaming\cache.ini
2013-07-31 17:43 - 2011-09-05 14:38 - 00000962 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1003UA.job
2013-07-31 17:40 - 2011-08-30 09:35 - 00000000 ____D C:\Users\JB\AppData\Roaming\Skype
2013-07-31 17:37 - 2013-03-03 17:51 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-31 16:45 - 2012-03-14 12:58 - 00000970 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA.job
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd.zip
2013-07-31 16:38 - 2013-07-31 16:38 - 00062125 _____ C:\Users\JB\Downloads\video_hd (1).zip
2013-07-31 16:31 - 2013-07-31 16:39 - 00090624 _____ C:\Users\JB\Desktop\video_hd.exe
2013-07-31 14:43 - 2011-09-05 14:38 - 00000910 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1003Core.job
2013-07-31 13:14 - 2013-07-31 13:14 - 00000000 _____ C:\Users\JB\Desktop\stažený soubor.htm
2013-07-30 22:03 - 2011-08-29 12:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core.job
2013-07-30 19:45 - 2012-03-14 12:58 - 00000948 _____ C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core.job
2013-07-30 09:22 - 2011-11-08 10:55 - 00000000 _____ C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2013-07-30 09:22 - 2011-09-13 21:14 - 00000052 _____ C:\Windows\SysWOW64\DOErrors.log
2013-07-30 01:07 - 2012-07-16 13:18 - 00003974 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{32C8AE03-4433-4784-9F4A-A70B78AA895A}
2013-07-29 19:26 - 2013-07-29 19:23 - 26419203 _____ C:\Users\JB\Desktop\Hudební dno.wmv
2013-07-29 09:49 - 2013-07-29 09:49 - 00001976 _____ C:\Users\JB\Downloads\Provozní na ubytovně Ostrava www.avizo.cz.url
2013-07-29 09:48 - 2013-07-29 09:48 - 00014093 _____ C:\Users\JB\Downloads\visa[1].html
2013-07-29 07:55 - 2011-09-17 18:20 - 00000000 ____D C:\Users\JB\AppData\Roaming\uTorrent
2013-07-28 22:25 - 2011-09-26 07:59 - 00000000 ___RD C:\Users\JB\Desktop\My Shared Folder
2013-07-28 19:39 - 2013-07-28 18:20 - 733585196 _____ C:\Users\JB\Desktop\Milionář-z-chatrče-CZ.avi
2013-07-28 17:47 - 2013-07-28 17:47 - 00000000 ____D C:\Users\JB\Desktop\F
2013-07-28 17:02 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-28 10:27 - 2013-07-28 10:27 - 00000031 _____ C:\Users\JB\Downloads\ostrava.mp3.m3u
2013-07-25 21:06 - 2013-07-25 21:06 - 00000000 ____D C:\Users\JB\Desktop\Big Bang theory CZ
2013-07-25 21:04 - 2013-07-25 21:04 - 00064193 _____ C:\Users\JB\Desktop\[CzT]Teorie_velkeho_tresku_Big_Bang_theory_1_5_serie_CZ_TVRip_.torrent
2013-07-25 20:38 - 2013-07-25 19:57 - 736137216 _____ C:\Users\JB\Desktop\Percy-Jackson-Zlodej-blesku-(Percy-Jackson-&-the-Olympians-The-Lightning-Thief).avi
2013-07-25 06:21 - 2013-07-25 06:17 - 00000000 ____D C:\Windows\system32\MRT
2013-07-18 18:28 - 2011-09-26 07:59 - 00000000 ____D C:\Users\JB\AppData\Local\Ares
2013-07-18 14:36 - 2009-07-14 06:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-18 14:36 - 2009-07-14 06:45 - 00023248 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-16 19:24 - 2013-07-14 19:25 - 00000000 ____D C:\Users\JB\Documents\Prototype
2013-07-16 09:22 - 2013-07-04 12:32 - 00003168 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJB
2013-07-16 09:22 - 2013-07-04 12:32 - 00000320 _____ C:\Windows\Tasks\HPCeeScheduleForJB.job
2013-07-16 09:22 - 2012-07-16 12:41 - 00003226 _____ C:\Windows\System32\Tasks\HPCeeScheduleForFBI_PROPERTY$
2013-07-16 09:22 - 2012-07-16 12:41 - 00000350 _____ C:\Windows\Tasks\HPCeeScheduleForFBI_PROPERTY$.job
2013-07-14 19:23 - 2013-07-14 19:23 - 00001612 _____ C:\Users\JB\Desktop\prototype.lnk
2013-07-14 19:20 - 2011-08-29 12:02 - 00429443 _____ C:\Windows\DirectX.log
2013-07-14 19:19 - 2013-07-14 19:11 - 00000000 ____D C:\Root
2013-07-14 19:19 - 2010-08-17 17:40 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-14 19:11 - 2013-03-03 18:33 - 00000000 ____D C:\Program Files (x86)\Activision
2013-07-13 19:31 - 2013-07-13 19:31 - 00002368 _____ C:\Users\JB\Downloads\Pomocný dělník ve výrobě - Volné pracovní místo OSTRAVA.url
2013-07-13 08:56 - 2013-07-13 08:56 - 29108498 _____ C:\Users\JB\Downloads\nedemo.zip
2013-07-12 21:58 - 2011-08-29 12:33 - 00003914 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000UA
2013-07-12 21:58 - 2011-08-29 12:33 - 00003518 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1716676511-3378767979-1263856736-1000Core
2013-07-12 14:04 - 2013-06-11 11:07 - 00000000 ____D C:\Program Files (x86)\Steam
2013-07-12 14:02 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-12 14:02 - 2009-07-14 06:51 - 00184316 _____ C:\Windows\setupact.log
2013-07-12 10:06 - 2013-07-11 09:17 - 00000000 ____D C:\Users\JB\Downloads\constantine
2013-07-11 12:33 - 2012-05-13 08:06 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-11 12:33 - 2012-05-13 08:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-11 10:53 - 2013-07-11 10:53 - 00071438 _____ C:\Users\JB\Downloads\[CzT]Harry-Potter-Komplet-CZ-by-James.torrent
2013-07-11 10:40 - 2013-07-11 09:48 - 935385786 _____ C:\Users\JB\Desktop\Zálesák---Forest-Warrior---Chuck-Norris--Rodinný-Dobrodružný-Komedie-Akční-USA,-1996,-budul-93-min-cz.avi
2013-07-11 09:16 - 2013-07-11 09:16 - 00019480 _____ C:\Users\JB\Downloads\[CzT]Constantine_Constantine_2005_.torrent
2013-07-11 09:15 - 2013-07-11 09:15 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ (1).torrent
2013-07-11 07:40 - 2011-08-29 17:52 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-10 18:37 - 2012-12-05 22:09 - 00000000 ____D C:\Users\JB\Desktop\Plocha
2013-07-10 18:29 - 2013-07-10 18:29 - 00013002 _____ C:\Users\JB\Downloads\[CzT]Hobit_Neocekavana_cesta_The_Hobbit_An_Unexpected_Journey_2012_CZ_.torrent
2013-07-09 17:21 - 2013-07-09 17:21 - 00001117 _____ C:\Users\JB\Downloads\Soustružník Ostrava-Kunčice Dobrá práce.cz (3).url
2013-07-08 20:59 - 2013-07-08 20:56 - 00000000 ____D C:\Users\JB\Desktop\Constantine
2013-07-08 20:50 - 2013-07-08 20:50 - 00011633 _____ C:\Users\JB\Downloads\[CzT]Constantine_CZ.torrent
2013-07-08 19:27 - 2013-07-08 20:03 - 03090483 _____ C:\Users\JB\Desktop\VID_20130708_192635.3gp
2013-07-08 13:35 - 2013-07-08 13:35 - 00001418 _____ C:\Users\JB\Downloads\vazač-ka, FRYMEL TRADE s.r.o. - Ostrava.url
2013-07-08 13:33 - 2013-07-08 13:32 - 00002239 _____ C:\Users\JB\Downloads\strážný-á - recepční, AVES Servisní a.s. - Ostrava.url
2013-07-08 07:30 - 2013-07-08 07:30 - 00001813 _____ C:\Users\JB\Desktop\993897_10201776920172561_133108716_n.jpg – zástupce.lnk
2013-07-06 17:50 - 2013-07-06 17:50 - 00000000 ____D C:\Users\JB\Desktop\Fretka
Files to move or delete:
====================
C:\Users\JB\AppData\Roaming\cache.dat
C:\Users\JB\AppData\Roaming\cache.ini
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
safeboot: ==> The system is configured to boot to Safe Mode <===== ATTENTION!
LastRegBack: 2013-07-03 11:45
==================== End Of Log ============================